Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-54835 - WordPress component
Unauthenticated Broken Access Control in Five Star Restaurant Menu
CVE-2026-54835
CVE-2026-54840 - WordPress component
Unauthenticated Broken Access Control in Newsletters
CVE-2026-54840
CVE-2026-54826 - WordPress component
Subscriber Insecure Direct Object References (IDOR) in SupportCandy
CVE-2026-54826
CVE-2026-54834 - WordPress component
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone
CVE-2026-54834
CVE-2026-54832 - WordPress component
Unauthenticated Broken Access Control in Gutenverse Companion
CVE-2026-54832
CVE-2026-54824 - WordPress component
Unauthenticated Sensitive Data Exposure in Ads by WPQuads
CVE-2026-54824
CVE-2026-54833 - WordPress component
Unauthenticated Backdoor in Enable CORS
CVE-2026-54833
CVE-2026-10835 - Before 3 Plugin
The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal permissions, such as subscribers, to perform SQL injection attacks.
CVE-2026-10835
CVE-2026-10823 - Ymc Filter Plugin
The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts.
CVE-2026-10823
CVE-2026-56053 - WordPress component
Subscriber PHP Object Injection in EventPrime
CVE-2026-56053
CVE-2026-56054 - WordPress component
Subscriber Arbitrary File Deletion in JS Help Desk
CVE-2026-56054
CVE-2026-56071 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Forminator
CVE-2026-56071
CVE-2026-56051 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in TablePress
CVE-2026-56051
CVE-2026-56049 - WordPress component
Contributor Remote Code Execution (RCE) in Post Snippets
CVE-2026-56049
CVE-2026-56042 - WordPress component
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce
CVE-2026-56042
CVE-2026-56014 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Master Slider
CVE-2026-56014
CVE-2026-56006 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in H5P
CVE-2026-56006
CVE-2026-54848 - APIExperts Square for WooCommerce Plugin
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.
CVE-2026-54848
CVE-2026-56005 - WordPress component
Subscriber Cross Site Scripting (XSS) in WP Activity Log
CVE-2026-56005
CVE-2026-54845 - WordPress component
Unauthenticated Local File Inclusion in MDTF
CVE-2026-54845
