Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 1-20 of 519 records
Threat Entry Updated 2026-07-13

CVE-2026-6801 - Context Blog Theme

The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup. This makes it possible for unauthenticated attackers to extract the content of password-protected posts.

THEME Context Blog

CVE-2026-6801

MEDIUM CVSS 5.3 2026-07-11
Threat Entry Updated 2026-07-10

CVE-2026-13710 - Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress Theme

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget's 'sg_body_description' parameter in versions up to, and including, 3.2.6. This is due to insufficient input sanitization and output escaping on the description attribute in the render_body() method of the Image_Box_View class — every other attribute used by the method is wrapped in esc_attr(), but the description value is concatenated directly into HTML body context. This makes it possible for authenticated attackers,…

THEME Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

CVE-2026-13710

MEDIUM CVSS 6.4 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-12685 - Escortwp Escortwp Theme

The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly transmits the site URL, administrator email address, and license key to a third-party server.

THEME Escortwp Escortwp

CVE-2026-12685

HIGH CVSS 7.5 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15291 - ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form Theme

The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin not performing any authentication and authorization checks. This makes it possible for unauthenticated attackers to extract sensitive data including customer names, email addresses, phone numbers, WhatsApp messages, complete geolocation data (IP addresses, city, country, ISP, coordinates), device fingerprinting information (browser, OS, screen resolution), and WordPress account credentials (user IDs,…

THEME ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form

CVE-2026-15291

HIGH CVSS 7.5 2026-07-10
Threat Entry Updated 2026-07-09

CVE-2026-4275 - Divi Torque Lite – Divi Modules for the Divi Builder & Theme

The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of '__return_true' as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress's built-in REST API nonce verification. Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification means that a forged cross-site request from a logged-in administrator's browser will pass the capability check via the admin's session cookies.…

THEME Divi Torque Lite – Divi Modules for the Divi Builder & Theme

CVE-2026-4275

HIGH CVSS 8.8 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-15158 - Blocksy Companion Theme

The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring via strpos() rather than validating that those strings appear as the final extension via PATHINFO_EXTENSION — allowing double-extension filenames such as shell.woff2.php to pass MIME validation and be handled as permitted font files. This makes it possible for unauthenticated attackers to upload files…

THEME Blocksy Companion

CVE-2026-15158

CRITICAL CVSS 9.8 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-12433 - Hydra Booking — Appointment Scheduling & Booking Calendar Theme

The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.2.1 via the /wp-json/hydra-booking/v1/booking/details/{id} REST endpoint. This is due to the getBookingDetails() callback only enforcing the tfhb_manage_options capability via tfhb_manage_options_permission(), without verifying that the requested booking belongs to the currently authenticated host (the lookup in getBookingDetailsData() filters solely on the booking id supplied in the URL). This makes it possible for authenticated attackers, with Hydra Host-level access and above (a role created by the plugin…

THEME Hydra Booking — Appointment Scheduling & Booking Calendar

CVE-2026-12433

MEDIUM CVSS 4.3 2026-07-09
Threat Entry Updated 2026-07-08

CVE-2026-6740 - Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder Theme

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

CVE-2026-6740

MEDIUM CVSS 6.4 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14250 - TH Login Registration Theme

The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled 'role' parameter and validating it only against get_editable_roles() — which returns every defined editable site role, including 'editor' — before passing it to wp_insert_user(). This makes it possible for unauthenticated attackers, when public user registration is enabled, to create new accounts with the editor role.

THEME TH Login Registration

CVE-2026-14250

MEDIUM CVSS 6.3 2026-07-08
Threat Entry Updated 2026-07-06

CVE-2026-5137 - RTMKit Theme

The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path validation on the 'template' parameter in the render_templates AJAX endpoint, which is used directly in a require/include statement without sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute files on the server ending in _templates.php, allowing the execution of any PHP code in those files.

THEME RTMKit

CVE-2026-5137

MEDIUM CVSS 4.3 2026-07-03
Threat Entry Updated 2026-07-06

CVE-2026-4804 - Zakra Theme

The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0. This is due to the theme registering three post meta fields (zakra_menu_item_color, zakra_menu_item_hover_color, and zakra_menu_item_active_color) with 'show_in_rest' => true and 'auth_callback' => '__return_true', but without any sanitize_callback parameter in the register_post_meta() calls. While the classic editor save path applies sanitize_hex_color() sanitization, the REST API path completely bypasses this protection. The unsanitized meta values are then retrieved via get_post_meta() and concatenated directly into CSS strings that are output…

THEME Zakra

CVE-2026-4804

MEDIUM CVSS 6.4 2026-07-03
Threat Entry Updated 2026-07-06

CVE-2026-11778 - CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x Theme

The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.2.14. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

THEME CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x

CVE-2026-11778

MEDIUM CVSS 5.4 2026-07-03
Threat Entry Updated 2026-07-06

CVE-2026-8351 - RTMKit Theme

The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in versions up to, and including, 2.0.7 This is due to insufficient output escaping on the 'background_text_heading' setting in the render() function, which concatenates the value directly into an HTML attribute without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME RTMKit

CVE-2026-8351

MEDIUM CVSS 6.4 2026-07-03
Threat Entry Updated 2026-07-02

CVE-2026-13252 - RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Theme

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'aspectRatio' Attribute in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

CVE-2026-13252

MEDIUM CVSS 6.4 2026-07-02
Threat Entry Updated 2026-07-02

CVE-2026-12472 - Kirki – Freeform Page Builder, Website Builder & Customizer Theme

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to send arbitrary HTML-injected emails — including phishing messages embedding a real, valid WordPress password-reset URL for the targeted user — to any registered user via the site's own mail server, abusing its SPF/DKIM reputation. The attacker-controlled emailSubject parameter…

THEME Kirki – Freeform Page Builder, Website Builder & Customizer

CVE-2026-12472

MEDIUM CVSS 5.3 2026-07-02
Threat Entry Updated 2026-07-02

CVE-2026-12122 - Kirki – Freeform Page Builder, Website Builder & Customizer Theme

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unauthenticated attackers to extract the full builder metadata and rendered HTML of any kirki_symbol post — including unpublished drafts — by supplying a sequential WordPress post ID.

THEME Kirki – Freeform Page Builder, Website Builder & Customizer

CVE-2026-12122

MEDIUM CVSS 5.3 2026-07-02
Threat Entry Updated 2026-07-02

CVE-2026-11600 - Envo's Templates & Widgets for Elementor and WooCommerce Theme

The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a user-controlled template/post ID directly to Elementor's get_builder_content_for_display() without verifying the referenced post's status (published/private/draft) or the visitor's authorization to view it. This makes it possible for authenticated attackers, with Author-level access and above, to disclose the contents of private…

THEME Envo's Templates & Widgets for Elementor and WooCommerce

CVE-2026-11600

MEDIUM CVSS 4.3 2026-07-02
Threat Entry Updated 2026-07-02

CVE-2026-10077 - Before 5 Theme

The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML attributes, which are permitted by wp_kses_post(), as markup, allowing users with the Author role to perform Stored Cross-Site Scripting attacks that execute in the browser of any user who views the affected post.

THEME Before 5

CVE-2026-10077

MEDIUM CVSS 6.8 2026-07-02
Scroll to top