Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 41-60 of 1249 records
Threat Entry Updated 2026-07-07

CVE-2026-12375 - Uncanny Automator Pro Plugin

The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.

PLUGIN Uncanny Automator Pro

CVE-2026-12375

CRITICAL CVSS 9.8 2026-07-07
Threat Entry Updated 2026-07-07

CVE-2026-4375 - Doleads Integrator Plugin

The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users.

PLUGIN Doleads Integrator

CVE-2026-4375

CRITICAL CVSS 9.0 2026-07-07
Threat Entry Updated 2026-07-06

CVE-2026-6382 - File Manager Pro Plugin

The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing authenticated users to perform OS Command Injection. This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensions.

PLUGIN File Manager Pro

CVE-2026-6382

CRITICAL CVSS 9.1 2026-07-06
Threat Entry Updated 2026-07-07

CVE-2026-9725 - Printcart Integration Plugin

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter sanitized only with sanitize_text_field() — which does not strip path traversal sequences — and then passes that path directly to Nbdesigner_IO::delete_folder() and PHP's rename(). The nonce protecting the nbd_save_customer_design AJAX action is freely obtainable by unauthenticated users via the nbd_check_use_logged_in endpoint. This makes…

PLUGIN Printcart Integration

CVE-2026-9725

CRITICAL CVSS 9.1 2026-07-03
Threat Entry Updated 2026-07-02

CVE-2026-5524 - Divi Form Builder Plugin

The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is directly interpolated into a regular expression used to validate uploaded files. Attackers can specify PHP-executable extensions such as .phtml, .phar, .php5, or .php7 to bypass the plugin's .htaccess protection which only blocks .php files specifically. Additionally, on Nginx-based servers, the .htaccess protection is…

PLUGIN Divi Form Builder

CVE-2026-5524

CRITICAL CVSS 9.8 2026-07-02
Threat Entry Updated 2026-07-01

CVE-2026-57692 - PrivateContent Plugin

Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.

PLUGIN PrivateContent

CVE-2026-57692

CRITICAL CVSS 9.8 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11387 - SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery Plugin

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full access to those accounts. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's…

PLUGIN SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

CVE-2026-11387

CRITICAL CVSS 9.8 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-6070 - Wp Businessdirectory Plugin

The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The task=upload.remove endpoint is accessible without authentication via the plugin's frontend routing system. The _filename parameter is accepted with RAW filter (no sanitization), and the helper function makePathFile() only normalizes directory separator characters without stripping path traversal sequences (../). When combined with the _path_type=2 parameter, which sets the base directory to the plugin's site folder, an…

PLUGIN Wp Businessdirectory

CVE-2026-6070

CRITICAL CVSS 9.1 2026-07-01
Threat Entry Updated 2026-06-30

CVE-2026-9711 - Eventon Wordpress Virtual Event Calendar Plugin

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter and lack of preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database, granted the "Enable additional search queries" setting is enabled and at least one published event exists.

PLUGIN Eventon Wordpress Virtual Event Calendar

CVE-2026-9711

CRITICAL CVSS 9.8 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-12073 - Groups And Communities Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't contain this parameter, and not properly handling the error messages. This makes it possible for unauthenticated attackers to change email address of user account with ID=1 (usually an administrator), and leverage that to reset the user's password and gain access to their account.

PLUGIN Groups And Communities

CVE-2026-12073

CRITICAL CVSS 9.8 2026-06-30
Scroll to top