Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4,286
Critical0
High4,286
Medium0
Reset
Showing 261-280 of 4286 records
Threat Entry Updated 2026-06-30

CVE-2026-12240 - Export User Data Plugin

The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Successful exploitation requires an administrator to trigger a user data export while a subscriber-level (or higher) user has stored a crafted serialized XLSXWriter…

PLUGIN Export User Data

CVE-2026-12240

HIGH CVSS 8.0 2026-06-30
Threat Entry Updated 2026-06-29

CVE-2026-57346 - Embed Privacy Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.

PLUGIN Embed Privacy

CVE-2026-57346

HIGH CVSS 7.1 2026-06-29
Threat Entry Updated 2026-06-29

CVE-2026-10083 - Apcu Manager Plugin

The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site Scripting vulnerability. When a persistent object cache is enabled, cache keys derived from unsanitised user input (e.g. a transient name created by another APCu Manager WordPress plugin before 4.5.0 from an unauthenticated request) are output without escaping and execute arbitrary JavaScript in the session of an administrator viewing the page.

PLUGIN Apcu Manager

CVE-2026-10083

HIGH CVSS 7.5 2026-06-29
Threat Entry Updated 2026-06-29

CVE-2026-8095 - Nmedia User File Uploader Plugin

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase evades the unset check and is normalized to wpfm_dir_path by sanitize_key() during update_post_meta(), allowing an attacker to overwrite the stored file path with an arbitrary filesystem path that is then passed directly to unlink() in delete_file_locally() without any directory containment validation. This makes it possible for…

PLUGIN Nmedia User File Uploader

CVE-2026-8095

HIGH CVSS 8.1 2026-06-28
Threat Entry Updated 2026-06-29

CVE-2026-10820 - Restrict Content Plugin

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active subscriptions via an Insecure Direct Object Reference.

PLUGIN Restrict Content

CVE-2026-10820

HIGH CVSS 8.1 2026-06-27
Scroll to top