Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 81-100 of 1249 records
Threat Entry Updated 2026-06-29

CVE-2026-57700 - OMGF Pro Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

PLUGIN OMGF Pro

CVE-2026-57700

CRITICAL CVSS 10.0 2026-06-25
Threat Entry Updated 2026-06-26

CVE-2026-54836 - YMC Filter Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5.

PLUGIN YMC Filter

CVE-2026-54836

CRITICAL CVSS 9.3 2026-06-25
Threat Entry Updated 2026-06-29

CVE-2026-12417 - SignUp & SignIn Plugin

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore accessible to unauthenticated users — performing no nonce verification, no capability check, and only a loose equality check between an attacker-supplied `reset_activation_code` POST parameter and the target user's `forgot_email` user meta value; when a user has never initiated a password reset, `get_user_meta()` returns an empty string that trivially…

PLUGIN SignUp & SignIn

CVE-2026-12417

CRITICAL CVSS 9.8 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-12416 - Invoice Generator Plugin

The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a loose equality comparison between the supplied `reset_activation_code` POST parameter and the target user's stored `forgot_email` user meta — a check that trivially evaluates to true (`'' == ''`) for any user who has never initiated a forgot-password request, which applies to administrators under…

PLUGIN Invoice Generator

CVE-2026-12416

CRITICAL CVSS 9.8 2026-06-24
Threat Entry Updated 2026-06-23

CVE-2026-11551 - Branda White Labeling Plugin

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Branda White Labeling

CVE-2026-11551

CRITICAL CVSS 9.8 2026-06-20
Threat Entry Updated 2026-06-22

CVE-2026-7515 - Betterdocs Pro Plugin

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

PLUGIN Betterdocs Pro

CVE-2026-7515

CRITICAL CVSS 9.8 2026-06-19
Threat Entry Updated 2026-06-22

CVE-2026-8713 - Fusion Builder Plugin

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The attack requires a published Avada form configured to save entries to the database; an unauthenticated attacker submits a path-traversal payload via the wp_ajax_nopriv_fusion_form_submit_ajax handler while also controlling…

PLUGIN Fusion Builder

CVE-2026-8713

CRITICAL CVSS 9.1 2026-06-19
Threat Entry Updated 2026-06-22

CVE-2026-38717 - the file upload function Plugin

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. The vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

PLUGIN the file upload function

CVE-2026-38717

CRITICAL CVSS 9.8 2026-06-18
Threat Entry Updated 2026-06-22

CVE-2026-38716 - the Python application export function Plugin

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

PLUGIN the Python application export function

CVE-2026-38716

CRITICAL CVSS 9.8 2026-06-18
Threat Entry Updated 2026-06-22

CVE-2026-38715 - the log viewing function Plugin

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

PLUGIN the log viewing function

CVE-2026-38715

CRITICAL CVSS 9.8 2026-06-18
Threat Entry Updated 2026-06-22

CVE-2026-38714 - the Python configuration function Plugin

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

PLUGIN the Python configuration function

CVE-2026-38714

CRITICAL CVSS 9.8 2026-06-18
Threat Entry Updated 2026-06-17

CVE-2026-54812 - Motors Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection. This issue affects Motors: from n/a through 1.4.109.

PLUGIN Motors

CVE-2026-54812

CRITICAL CVSS 9.3 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54819 - Listdom Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.

PLUGIN Listdom

CVE-2026-54819

CRITICAL CVSS 9.3 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54815 - Cargo Shipping Location for WooCommerce Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.

PLUGIN Cargo Shipping Location for WooCommerce

CVE-2026-54815

CRITICAL CVSS 9.3 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54809 - GIFT4U Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: from n/a through 1.0.10.

PLUGIN GIFT4U

CVE-2026-54809

CRITICAL CVSS 9.3 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54808 - WP Travel Gutenberg Blocks Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.

PLUGIN WP Travel Gutenberg Blocks

CVE-2026-54808

CRITICAL CVSS 9.3 2026-06-17
Scroll to top