Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4,286
Critical0
High4,286
Medium0
Reset
Showing 1-20 of 4286 records
Threat Entry Updated 2026-07-21

CVE-2026-65052 - Ninja Forms Plugin

Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured option in ListSelect or ListRadio fields. Attackers can tamper with form submission payloads to the ajax submit endpoint, causing the get_calc_value() method to fail open and return attacker-controlled values, enabling manipulation of payment amounts to zero or arbitrary figures and bypassing admin-configured pricing logic.

PLUGIN Ninja Forms

CVE-2026-65052

HIGH CVSS 8.7 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-65050 - Ninja Forms Plugin

Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email…

PLUGIN Ninja Forms

CVE-2026-65050

HIGH CVSS 7.1 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-65049 - Ninja Forms Plugin

Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switch_to_blog(), dropping all nf3_* tables and clearing options and transients across every subsite in the network without requiring super-admin or…

PLUGIN Ninja Forms

CVE-2026-65049

HIGH CVSS 8.4 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-1771 - Mapsvg Lite Interactive Vector Maps Plugin

The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that prevents file validation from taking place. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Mapsvg Lite Interactive Vector Maps

CVE-2026-1771

HIGH CVSS 7.2 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-8082 - Bpost Shipping Platform Plugin

The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this bpost-shipping-platform WordPress plugin before 3.2.3.

PLUGIN Bpost Shipping Platform

CVE-2026-8082

HIGH CVSS 7.5 2026-07-21
Threat Entry Updated 2026-08-04

CVE-2026-60137 - WordPress component

WordPress Core SQL Injection Vulnerability Vendor/Product: WordPress Core Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ;…

UNKNOWN WordPress component

CVE-2026-60137

HIGH CVSS 5.9 2026-07-21
Threat Entry Updated 2026-07-20

CVE-2026-9833 - Tag Groups Is The Advanced Way To Display Your Taxonomy Terms Plugin

The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in the response body served with an HTML content type, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of a logged-in user with `edit_pages` capability (Editor or higher) who is tricked into following a crafted link.

PLUGIN Tag Groups Is The Advanced Way To Display Your Taxonomy Terms

CVE-2026-9833

HIGH CVSS 7.1 2026-07-20
Threat Entry Updated 2026-07-21

CVE-2026-13142 - Email Otp Plugin

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, leading to full site takeover.

PLUGIN Email Otp

CVE-2026-13142

HIGH CVSS 8.1 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12970 - Before 4 Plugin

The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link.

PLUGIN Before 4

CVE-2026-12970

HIGH CVSS 7.1 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-11349 - Modern Event Calendar Pro Plugin

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.

PLUGIN Modern Event Calendar Pro

CVE-2026-11349

HIGH CVSS 8.6 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12592 - Slimstat Analytics Plugin

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider.

PLUGIN Slimstat Analytics

CVE-2026-12592

HIGH CVSS 7.5 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-10081 - Unlimited Elements For Elementor Plugin

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor (including administrators) of any WP page displaying that Place ID's reviews.

PLUGIN Unlimited Elements For Elementor

CVE-2026-10081

HIGH CVSS 8.8 2026-07-20
Threat Entry Updated 2026-07-17

CVE-2026-11961 - Before 5 Plugin

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exists.

PLUGIN Before 5

CVE-2026-11961

HIGH CVSS 8.1 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-11575 - Phonepe Payment Solutions Plugin

The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces to an unkeyed hash of the request body that anyone can compute. This allows unauthenticated attackers to forge a payment-success notification and mark unpaid WooCommerce orders as paid without any payment being made.

PLUGIN Phonepe Payment Solutions

CVE-2026-11575

HIGH CVSS 7.5 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-13765 - Wordpress Lms Plugin For Create And Sell Online Courses

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, explanations, and question content for any quiz question on the site — including questions belonging to paid courses the attacker is not enrolled in.

PLUGIN Wordpress Lms Plugin For Create And Sell Online Courses

CVE-2026-13765

HIGH CVSS 7.5 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-13352 - Wp User Avatar Plugin

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the global WordPress MIME allowlist, without scoping the expansion to digital-product upload contexts. This makes it possible for authenticated attackers, with author-level access and above, to upload files that may be executable,…

PLUGIN Wp User Avatar

CVE-2026-13352

HIGH CVSS 8.8 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15395 - Kali Forms Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The required form-submission nonce is publicly available on any page containing the form shortcode, making this exploitable by fully unauthenticated attackers without any precondition beyond the form being…

PLUGIN Kali Forms

CVE-2026-15395

HIGH CVSS 7.2 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-7543 - Breakdance Plugin

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Breakdance

CVE-2026-7543

HIGH CVSS 7.2 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15103 - One Click Upsell Plugin

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This is due to the `update_settings()` REST callback failing to validate the `group_id` path parameter against an allowlist of permitted option names before passing it directly to `get_option()` and `update_option()`, allowing the built-in `wp_user_roles` option — which satisfies the route's loose `[\w-]+` regex — to be targeted. This makes it possible for authenticated attackers with the `wpf_manage_funnels`…

PLUGIN One Click Upsell

CVE-2026-15103

HIGH CVSS 8.8 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15005 - Loco Translate Plugin

The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the 'template' parameter, which bypasses path validation and is passed directly to the include sink in execTemplate() via a forged request granted they can trick a site administrator into performing an action such as…

PLUGIN Loco Translate

CVE-2026-15005

HIGH CVSS 8.8 2026-07-16
Scroll to top