Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 361-380 of 1249 records
Threat Entry Updated 2026-02-27

CVE-2025-12981 - Listee Theme

The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bundled listee-core plugin's user registration function that fails to properly sanitize the user_role parameter. This makes it possible for unauthenticated attackers to register as Administrator by manipulating the user_role parameter during registration.

THEME Listee

CVE-2025-12981

CRITICAL CVSS 9.8 2026-02-27
Threat Entry Updated 2026-06-17

CVE-2026-23693 - Elementskit Lite Plugin

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and insufficiently validates certain parameters, including the list parameter, when constructing upstream Mailchimp API requests. An unauthenticated attacker can abuse the endpoint as an open proxy to Mailchimp, potentially triggering unauthorized API calls, manipulating subscription data, exhausting API quotas, or causing resource consumption on the affected WordPress site.

PLUGIN Elementskit Lite

CVE-2026-23693

CRITICAL CVSS 9.3 2026-02-23
Threat Entry Updated 2026-06-17

CVE-2026-24956 - Download Manager Addons for Elementor Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download Manager Addons for Elementor wpdm-elementor allows Blind SQL Injection.This issue affects Download Manager Addons for Elementor: from n/a through

PLUGIN Download Manager Addons for Elementor

CVE-2026-24956

CRITICAL CVSS 9.3 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22384 - Applay - Shortcodes Plugin

Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay - Shortcodes: from n/a through

PLUGIN Applay - Shortcodes

CVE-2026-22384

CRITICAL CVSS 9.8 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22365 - Soleng Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Soleng soleng allows PHP Local File Inclusion.This issue affects Soleng: from n/a through

PLUGIN Soleng

CVE-2026-22365

CRITICAL CVSS 9.8 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-23549 - WpEvently Plugin

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through

PLUGIN WpEvently

CVE-2026-23549

CRITICAL CVSS 9.8 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-23542 - Grand Restaurant Plugin

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through

PLUGIN Grand Restaurant

CVE-2026-23542

CRITICAL CVSS 9.8 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-1994 - s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions Plugin

The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions

CVE-2026-1994

CRITICAL CVSS 9.8 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-1405 - Slider Future Plugin

The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Slider Future

CVE-2026-1405

CRITICAL CVSS 9.8 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-0926 - Prodigy Commerce Plugin

The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'parameters[template_name]' parameter. This makes it possible for unauthenticated attackers to include and read arbitrary files or execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Prodigy Commerce

CVE-2026-0926

CRITICAL CVSS 9.8 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-13851 - Buyent Classified Plugin

The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.0.7. This is due to the plugin not validating or restricting the user role during registration via the REST API endpoint. This makes it possible for unauthenticated attackers to register accounts with arbitrary roles, including administrator, by manipulating the _buyent_classified_user_type parameter during the registration process, granting them complete control over the WordPress site.

PLUGIN Buyent Classified

CVE-2025-13851

CRITICAL CVSS 9.8 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-13563 - Lizza Lms Pro Plugin

The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_lms_pro_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

PLUGIN Lizza Lms Pro

CVE-2025-13563

CRITICAL CVSS 9.8 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-12882 - Clasifico Listing Plugin

The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin allowing users who are registering new accounts to set their own role by supplying the 'listing_user_role' parameter. This makes it possible for unauthenticated attackers to gain elevated privileges by registering an account with the administrator role.

PLUGIN Clasifico Listing

CVE-2025-12882

CRITICAL CVSS 9.8 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-1937 - Woocommerce Email Customizer Plugin

The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yaymail_import_state` AJAX action in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

PLUGIN Woocommerce Email Customizer

CVE-2026-1937

CRITICAL CVSS 9.8 2026-02-18
Threat Entry Updated 2026-06-17

CVE-2026-1490 - Cleantalk Spam Protect Plugin

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. Note: This is only exploitable on sites with an invalid API key.

PLUGIN Cleantalk Spam Protect

CVE-2026-1490

CRITICAL CVSS 9.8 2026-02-15
Threat Entry Updated 2026-02-18

CVE-2025-8572 - Truelysell Core Plugin

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated privileges, including administrator access.

PLUGIN Truelysell Core

CVE-2025-8572

CRITICAL CVSS 9.8 2026-02-14
Threat Entry Updated 2026-06-17

CVE-2026-1306 - Midi Synth Plugin

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible granted the attacker can obtain a valid nonce. The nonce is exposed in frontend JavaScript making it trivially accessible to unauthenticated attackers.

PLUGIN Midi Synth

CVE-2026-1306

CRITICAL CVSS 9.8 2026-02-14
Threat Entry Updated 2026-02-12

CVE-2025-14892 - Prime Listing Manager Plugin

The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret.

PLUGIN Prime Listing Manager

CVE-2025-14892

CRITICAL CVSS 9.8 2026-02-12
Threat Entry Updated 2026-06-17

CVE-2026-1729 - AdForest Plugin

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.

PLUGIN AdForest

CVE-2026-1729

CRITICAL CVSS 9.8 2026-02-12
Threat Entry Updated 2026-06-17

CVE-2026-1357 - Wpvivid Backuprestore Plugin

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files. When the plugin fails to decrypt a session key using openssl_private_decrypt(), it does not terminate execution and instead passes the boolean false value to the phpseclib library's AES cipher initialization. The library treats this false value as a string of null…

PLUGIN Wpvivid Backuprestore

CVE-2026-1357

CRITICAL CVSS 9.8 2026-02-11
Scroll to top