Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-11590 - Wp Support Plus Responsive Ticket System Plugin
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys before using them in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
CVE-2026-11590
CVE-2026-12240 - Export User Data Plugin
The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Successful exploitation requires an administrator to trigger a user data export while a subscriber-level (or higher) user has stored a crafted serialized XLSXWriter…
CVE-2026-12240
CVE-2026-57338 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in ARForms
CVE-2026-57338
CVE-2026-57337 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder
CVE-2026-57337
CVE-2026-57336 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Jobify
CVE-2026-57336
CVE-2026-57333 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free
CVE-2026-57333
CVE-2026-57332 - WordPress component
Subscriber Broken Access Control in Wallet System for WooCommerce
CVE-2026-57332
CVE-2026-57320 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in BEAR
CVE-2026-57320
CVE-2026-57346 - Embed Privacy Plugin
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.
CVE-2026-57346
CVE-2026-10083 - Apcu Manager Plugin
The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site Scripting vulnerability. When a persistent object cache is enabled, cache keys derived from unsanitised user input (e.g. a transient name created by another APCu Manager WordPress plugin before 4.5.0 from an unauthenticated request) are output without escaping and execute arbitrary JavaScript in the session of an administrator viewing the page.
CVE-2026-10083
CVE-2026-8095 - Nmedia User File Uploader Plugin
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase evades the unset check and is normalized to wpfm_dir_path by sanitize_key() during update_post_meta(), allowing an attacker to overwrite the stored file path with an arbitrary filesystem path that is then passed directly to unlink() in delete_file_locally() without any directory containment validation. This makes it possible for…
CVE-2026-8095
CVE-2026-10820 - Restrict Content Plugin
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active subscriptions via an Insecure Direct Object Reference.
CVE-2026-10820
CVE-2026-57667 - WordPress component
Sales Representative SQL Injection in Groundhogg
CVE-2026-57667
CVE-2026-57663 - WordPress component
Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes
CVE-2026-57663
CVE-2026-57662 - WordPress component
Contributor SQL Injection in Contest Gallery
CVE-2026-57662
CVE-2026-57659 - WordPress component
Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin
CVE-2026-57659
CVE-2026-57653 - WordPress component
Contributor SQL Injection in WP Job Portal
CVE-2026-57653
CVE-2026-57655 - WordPress component
Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard
CVE-2026-57655
CVE-2026-57644 - WordPress component
Contributor SQL Injection in Restaurant Menu by MotoPress
CVE-2026-57644
CVE-2026-57645 - WordPress component
newsletters_subscribers Broken Access Control in Newsletters
CVE-2026-57645
