Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 1-20 of 1249 records
Threat Entry Updated 2026-07-21

CVE-2026-65048 - Ninja Forms Plugin

Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administrator's browser when viewing submissions in the WordPress admin panel, enabling session-cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site…

PLUGIN Ninja Forms

CVE-2026-65048

CRITICAL CVSS 9.3 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-13439 - Easy Form Builder Plugin

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a publicly-accessible nonce refresh endpoint (Emsfb/v1/nonce/refresh) that issues valid WordPress REST nonces to unauthenticated visitors. This makes it possible for unauthenticated attackers to reset the password of any WordPress user — including administrators — by scraping the public sid from a published…

PLUGIN Easy Form Builder

CVE-2026-13439

CRITICAL CVSS 9.8 2026-07-21
Threat Entry Updated 2026-07-24

CVE-2026-63030 - WordPress Core

WordPress Core Interpretation Conflict Vulnerability Vendor/Product: WordPress Core Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ;…

CORE WordPress Core

CVE-2026-63030

CRITICAL CVSS 9.8 2026-07-21
Threat Entry Updated 2026-07-20

CVE-2026-13147 - Before 6 Plugin

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).

PLUGIN Before 6

CVE-2026-13147

CRITICAL CVSS 9.1 2026-07-20
Threat Entry Updated 2026-07-17

CVE-2026-9810 - Ai Copilot Plugin

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.

PLUGIN Ai Copilot

CVE-2026-9810

CRITICAL CVSS 9.8 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15982 - Automation Toolkit Plugin

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.

PLUGIN Automation Toolkit

CVE-2026-15982

CRITICAL CVSS 9.8 2026-07-17
Threat Entry Updated 2026-07-21

CVE-2026-14956 - Bricksforge Plugin

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to the trusted form-field whitelist. This makes it possible for unauthenticated attackers to register a new administrator account by submitting a crafted request to a publicly accessible Bricksforge Pro Forms registration form. Successful exploitation requires that the site has a public Bricksforge Pro Forms element configured with the…

PLUGIN Bricksforge

CVE-2026-14956

CRITICAL CVSS 9.8 2026-07-17
Threat Entry Updated 2026-07-16

CVE-2026-12492 - Happy Coders Otp Login For Woocommerce Plugin

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.

PLUGIN Happy Coders Otp Login For Woocommerce

CVE-2026-12492

CRITICAL CVSS 9.8 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15013 - Miniorange Saml 20 Single Sign On Plugin

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the attacker-controlled `SAMLResponse` parameter rather than enforcing the locally configured algorithm, causing the plugin to recast the IdP's RSA public key as an HMAC-SHA1 shared secret and validate the forged signature against it. This makes it possible for unauthenticated attackers to forge a SAML assertion targeting any WordPress account…

PLUGIN Miniorange Saml 20 Single Sign On

CVE-2026-15013

CRITICAL CVSS 9.8 2026-07-16
Threat Entry Updated 2026-07-14

CVE-2026-13001 - Podlove Podcasting Plugin For Wordpress

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Podlove Podcasting Plugin For Wordpress

CVE-2026-13001

CRITICAL CVSS 9.8 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-11563 - Word Count And Social Shares Plugin

The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g. by deleting wp-config.php).

PLUGIN Word Count And Social Shares

CVE-2026-11563

CRITICAL CVSS 9.6 2026-07-14
Threat Entry Updated 2026-07-13

CVE-2026-57811 - Realtyna Organic IDX plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through

PLUGIN Realtyna Organic IDX plugin

CVE-2026-57811

CRITICAL CVSS 10.0 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-59518 - Directorist Plugin

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through

PLUGIN Directorist

CVE-2026-59518

CRITICAL CVSS 9.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57813 - MailOptin Plugin

Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through

PLUGIN MailOptin

CVE-2026-57813

CRITICAL CVSS 9.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-59515 - AIWU Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through

PLUGIN AIWU

CVE-2026-59515

CRITICAL CVSS 9.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57770 - Grand Photography Plugin

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through

PLUGIN Grand Photography

CVE-2026-57770

CRITICAL CVSS 9.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57744 - RT-Theme 18 | Extensions

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through

THEME RT-Theme 18 | Extensions

CVE-2026-57744

CRITICAL CVSS 9.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57738 - 777 Plugin

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through

PLUGIN 777

CVE-2026-57738

CRITICAL CVSS 9.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57739 - AcyMailing SMTP Newsletter Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through

PLUGIN AcyMailing SMTP Newsletter

CVE-2026-57739

CRITICAL CVSS 9.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57724 - Kirki Plugin

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through

PLUGIN Kirki

CVE-2026-57724

CRITICAL CVSS 9.8 2026-07-13
Scroll to top