Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-12415 - Invoice Creator Plugin
The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account, accepts an attacker-controlled user_id and user_email from POST data, and calls wp_update_user() without verifying authentication, ownership, or a nonce. This makes it possible for unauthenticated attackers to change the email address of any user, including administrators, and then trigger WordPress's password reset flow to gain access to the targeted account.
CVE-2026-12415
CVE-2026-57658 - WordPress component
Administrator Arbitrary File Upload in TemplateSpare
CVE-2026-57658
CVE-2026-56070 - WordPress component
Unauthenticated SQL Injection in Advance Product Search
CVE-2026-56070
CVE-2026-56068 - WordPress component
Unauthenticated SQL Injection in JetEngine
CVE-2026-56068
CVE-2026-56067 - WordPress component
Unauthenticated SQL Injection in JetSmartFilters
CVE-2026-56067
CVE-2026-56059 - WordPress component
Subscriber Arbitrary File Upload in Travel Booking
CVE-2026-56059
CVE-2026-56058 - WordPress component
Subscriber Arbitrary File Upload in Quform
CVE-2026-56058
CVE-2026-56057 - WordPress component
Subscriber PHP Object Injection in Uncanny Automator Pro
CVE-2026-56057
CVE-2026-56062 - WordPress component
Unauthenticated SQL Injection in Quotes llama
CVE-2026-56062
CVE-2026-56033 - WordPress component
Unauthenticated Privilege Escalation in Dokan Pro
CVE-2026-56033
CVE-2026-56032 - WordPress component
Subscriber PHP Object Injection in Buddyboss Platform
CVE-2026-56032
CVE-2026-56036 - WordPress component
Unauthenticated SQL Injection in 워드프레스 결제 심플페이
CVE-2026-56036
CVE-2026-56034 - WordPress component
Unauthenticated SQL Injection in Library Management System
CVE-2026-56034
CVE-2026-56027 - WordPress component
Customer Arbitrary File Upload in Booster for WooCommerce
CVE-2026-56027
CVE-2026-56030 - WordPress component
Unauthenticated Privilege Escalation in Paytium
CVE-2026-56030
CVE-2026-56028 - Easy Elements for Elementor – Addons & Website Templates Theme
Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates
CVE-2026-56028
CVE-2026-54831 - WordPress component
Unauthenticated SQL Injection in GeoDirectory
CVE-2026-54831
CVE-2026-54827 - WordPress component
Unauthenticated SQL Injection in Real Estate 7
CVE-2026-54827
CVE-2026-54825 - WordPress component
Unauthenticated SQL Injection in wpDataTables
CVE-2026-54825
CVE-2026-54820 - WordPress component
Unauthenticated SQL Injection in JetBooking
CVE-2026-54820
