Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 181-200 of 1249 records
Threat Entry Updated 2026-06-17

CVE-2026-52704 - WooCommerce PDF Invoice Builder Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.

PLUGIN WooCommerce PDF Invoice Builder

CVE-2026-52704

CRITICAL CVSS 10.0 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-8935 - Wp Maps Pro Plugin

The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.

PLUGIN Wp Maps Pro

CVE-2026-8935

CRITICAL CVSS 9.8 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-47365 - WordPress-Toolkit Plugin

Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.

PLUGIN WordPress-Toolkit

CVE-2026-47365

CRITICAL CVSS 9.9 2026-06-12
Threat Entry Updated 2026-06-17

CVE-2026-42647 - JoomSport Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7.

PLUGIN JoomSport

CVE-2026-42647

CRITICAL CVSS 9.3 2026-06-11
Threat Entry Updated 2026-06-17

CVE-2026-39494 - Product Filter by WBW Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter by WBW: from n/a through 3.1.2.

PLUGIN Product Filter by WBW

CVE-2026-39494

CRITICAL CVSS 9.3 2026-06-11
Threat Entry Updated 2026-06-17

CVE-2026-9067 - Before 1 Plugin

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by WordPress's media library through endpoints that should only accept images or videos.

PLUGIN Before 1

CVE-2026-9067

CRITICAL CVSS 9.1 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-10580 - Hippoo Mobile App For Woocommerce Plugin

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both administrators and unauthenticated visitors — a value that HippooPermissions::has_role_access() unconditionally interprets as full administrator access — causing override_extension_permission_callback() to assign __return_true as the permission callback for every WordPress and WooCommerce REST route cloned under /wc-hippoo/v1/ext/ by HippooControllerWithAuth::re_register_external_routes(), while the block_unauthorized_access() pre-dispatch guard fails to block unauthenticated…

PLUGIN Hippoo Mobile App For Woocommerce

CVE-2026-10580

CRITICAL CVSS 9.8 2026-06-05
Threat Entry Updated 2026-06-17

CVE-2026-49777 - Product Slider Pro for WooCommerce Plugin

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.3. No patched version is available - the vendor has applied a fix to an existing release without publishing a new version. While the patch provided by the vendor is valid, releasing it under the existing version number leaves users unable to reliably determine whether they are running a patched or vulnerable installation. As a result, we treat this…

PLUGIN Product Slider Pro for WooCommerce

CVE-2026-49777

CRITICAL CVSS 10.0 2026-06-05
Threat Entry Updated 2026-06-17

CVE-2026-5076 - Armember Premium Plugin

The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a password reset. This is in addition to the hashed key that WordPress core stores securely in `wp_users.user_activation_key`. The plaintext key stored in `wp_usermeta` can be used with the plugin's custom `armrp` reset action to set a new password for any user. Combined with another vulnerability such…

PLUGIN Armember Premium

CVE-2026-5076

CRITICAL CVSS 9.8 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-0611 - WordPress component

Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI endpoints. Attackers can write ASPX webshells to the IIS wwwroot directory to achieve unauthenticated remote code execution on the system. Port 8989 is not exposed in a default Sentinel installation; exploitation requires that the .NET Remoting port has been explicitly made network-accessible through deliberate configuration…

UNKNOWN WordPress component

CVE-2026-0611

CRITICAL CVSS 9.2 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-42684 - WP Job Portal Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1.

PLUGIN WP Job Portal

CVE-2026-42684

CRITICAL CVSS 9.3 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-8206 - Kirki Plugin

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.

PLUGIN Kirki

CVE-2026-8206

CRITICAL CVSS 9.8 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-42672 - WP Directory Kit Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.1.

PLUGIN WP Directory Kit

CVE-2026-42672

CRITICAL CVSS 9.3 2026-06-01
Threat Entry Updated 2026-06-17

CVE-2026-48879 - AIWU Plugin

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

PLUGIN AIWU

CVE-2026-48879

CRITICAL CVSS 9.8 2026-06-01
Scroll to top