Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-14352 - Ar For Woocommerce Plugin
The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The three intended access controls all fail: valid nonces are freely minted by unauthenticated callers via the nopriv ar_get_fresh_nonce and ar_process_user_image AJAX handlers; the AES-256-CBC encryption key is derived from get_option('ar_licence_key'), which returns false on default free installations and yields a predictable key…
CVE-2026-14352
CVE-2026-13040 - Nex Forms Express Wp Form Builder Plugin
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The submission endpoint is registered via wp_ajax_nopriv_submit_nex_form with no nonce verification, making it fully accessible to unauthenticated attackers without any CSRF token.
CVE-2026-13040
CVE-2026-14327 - Ar For Wordpress Plugin
The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires an attacker to first obtain a valid nonce and secure nonce via the publicly accessible ar_get_fresh_nonce and ar_process_user_image nopriv AJAX handlers, and to reproduce the encryption key locally — both steps are fully achievable by an unauthenticated attacker on any default…
CVE-2026-14327
CVE-2026-7311 - Tiny Compress Images Plugin
The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_converted_image_size function in all versions up to, and including, 3.6.13. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). An attacker can exploit this by injecting an arbitrary server file path into the 'convert.path' field of the…
CVE-2026-7311
CVE-2026-57766 - WordPress component
Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor
CVE-2026-57766
CVE-2026-57765 - WordPress component
Contributor SQL Injection in WP EasyCart
CVE-2026-57765
CVE-2026-57761 - WordPress component
Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP
CVE-2026-57761
CVE-2026-57759 - WordPress component
Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid
CVE-2026-57759
CVE-2026-57756 - WordPress component
Contributor SQL Injection in nicen-localize-image
CVE-2026-57756
CVE-2026-57752 - WordPress component
Contributor SQL Injection in iNET Webkit 1.2.4 versions.
CVE-2026-57752
CVE-2026-57758 - WordPress component
Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce
CVE-2026-57758
CVE-2026-57757 - WordPress component
Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup
CVE-2026-57757
CVE-2026-57751 - WordPress component
Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login
CVE-2026-57751
CVE-2026-57749 - WordPress component
Contributor Local File Inclusion in SportsPress Pro
CVE-2026-57749
CVE-2026-57748 - WordPress component
Contributor Local File Inclusion in Shopify
CVE-2026-57748
CVE-2026-57746 - WordPress component
Subscriber Broken Access Control in Booked
CVE-2026-57746
CVE-2026-57687 - WordPress component
Contributor SQL Injection in Custom Field Template
CVE-2026-57687
CVE-2026-57688 - WordPress component
Unauthenticated Broken Access Control in POS Entegratör
CVE-2026-57688
CVE-2026-57686 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in WowAddons
CVE-2026-57686
CVE-2026-57682 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory
CVE-2026-57682
