Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-12375 - Uncanny Automator Pro Plugin
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.
CVE-2026-12375
CVE-2026-4375 - Doleads Integrator Plugin
The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users.
CVE-2026-4375
CVE-2026-6382 - File Manager Pro Plugin
The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing authenticated users to perform OS Command Injection. This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensions.
CVE-2026-6382
CVE-2026-9725 - Printcart Integration Plugin
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter sanitized only with sanitize_text_field() — which does not strip path traversal sequences — and then passes that path directly to Nbdesigner_IO::delete_folder() and PHP's rename(). The nonce protecting the nbd_save_customer_design AJAX action is freely obtainable by unauthenticated users via the nbd_check_use_logged_in endpoint. This makes…
CVE-2026-9725
CVE-2026-5524 - Divi Form Builder Plugin
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is directly interpolated into a regular expression used to validate uploaded files. Attackers can specify PHP-executable extensions such as .phtml, .phar, .php5, or .php7 to bypass the plugin's .htaccess protection which only blocks .php files specifically. Additionally, on Nginx-based servers, the .htaccess protection is…
CVE-2026-5524
CVE-2026-57683 - WordPress component
Unauthenticated SQL Injection in WP Fast Total Search
CVE-2026-57683
CVE-2026-57677 - WordPress component
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce
CVE-2026-57677
CVE-2026-57679 - WordPress component
Unauthenticated SQL Injection in GeekyBot
CVE-2026-57679
CVE-2026-57624 - WordPress component
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro
CVE-2026-57624
CVE-2026-57621 - WordPress component
Unauthenticated PHP Object Injection in Booktics
CVE-2026-57621
CVE-2026-57625 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro
CVE-2026-57625
CVE-2026-57623 - WordPress component
Unauthenticated Arbitrary Code Execution in W3 Total Cache
CVE-2026-57623
CVE-2026-27436 - WordPress component
Editor Arbitrary Code Execution in Five Star Business Profile and Schema
CVE-2026-27436
CVE-2026-27419 - WordPress component
Subscriber Arbitrary File Upload in Zegen
CVE-2026-27419
CVE-2026-57692 - PrivateContent Plugin
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.
CVE-2026-57692
CVE-2026-11387 - SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery Plugin
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full access to those accounts. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's…
CVE-2026-11387
CVE-2026-6070 - Wp Businessdirectory Plugin
The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The task=upload.remove endpoint is accessible without authentication via the plugin's frontend routing system. The _filename parameter is accepted with RAW filter (no sanitization), and the helper function makePathFile() only normalizes directory separator characters without stripping path traversal sequences (../). When combined with the _path_type=2 parameter, which sets the base directory to the plugin's site folder, an…
CVE-2026-6070
CVE-2026-9711 - Eventon Wordpress Virtual Event Calendar Plugin
The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter and lack of preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database, granted the "Enable additional search queries" setting is enabled and at least one published event exists.
CVE-2026-9711
CVE-2026-12073 - Groups And Communities Plugin
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't contain this parameter, and not properly handling the error messages. This makes it possible for unauthenticated attackers to change email address of user account with ID=1 (usually an administrator), and leverage that to reset the user's password and gain access to their account.
CVE-2026-12073
CVE-2026-57331 - WordPress component
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site
CVE-2026-57331
