Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-40749 - WordPress component
Subscriber Arbitrary File Upload in Charity Zone
CVE-2026-40749
CVE-2026-40748 - WordPress component
Subscriber Arbitrary File Upload in Kids Gift Shop
CVE-2026-40748
CVE-2026-40747 - WordPress component
Subscriber Arbitrary File Upload in Ecommerce Zone
CVE-2026-40747
CVE-2026-40746 - WordPress component
Subscriber Arbitrary File Upload in Restaurant Zone
CVE-2026-40746
CVE-2026-40725 - WordPress component
Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.
CVE-2026-40725
CVE-2026-39589 - WordPress component
Subscriber Arbitrary File Upload in Webenvo
CVE-2026-39589
CVE-2026-39596 - WordPress component
Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.
CVE-2026-39596
CVE-2026-39529 - WordPress component
Unauthenticated PHP Object Injection in Elementra
CVE-2026-39529
CVE-2026-39438 - WordPress component
Unauthenticated SQL Injection in ListingPro
CVE-2026-39438
CVE-2026-27429 - WordPress component
Unauthenticated PHP Object Injection in Nifty
CVE-2026-27429
CVE-2026-27041 - Elementor Plugin
Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium)
CVE-2026-27041
CVE-2026-27395 - WordPress component
Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
CVE-2026-27395
CVE-2026-25470 - Custom Post Types Plugin
Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.
CVE-2026-25470
CVE-2026-25446 - WordPress component
Subscriber Arbitrary File Upload in WishList Member X
CVE-2026-25446
CVE-2026-24611 - WordPress component
Unauthenticated Broken Access Control in MetForm Pro
CVE-2026-24611
CVE-2026-22340 - WordPress component
Unauthenticated SQL Injection in WPJobster
CVE-2026-22340
CVE-2026-22332 - WordPress component
Unauthenticated SQL Injection in Tutor LMS Pro
CVE-2026-22332
CVE-2026-22327 - WordPress component
Subscriber Arbitrary File Upload in Restaurt
CVE-2026-22327
CVE-2026-40750 - Kids Online Store Plugin
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.
CVE-2026-40750
CVE-2026-52715 - WordPress Core
Unauthenticated SQL Injection in GEO my WordPress
CVE-2026-52715
