Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4,286
Critical0
High4,286
Medium0
Reset
Showing 21-40 of 4286 records
Threat Entry Updated 2026-07-17

CVE-2026-15008 - Uncanny Automator Plugin

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires a Forminator form connected to an Uncanny Automator recipe configured for 'Everyone', allowing unauthenticated form submissions to supply…

PLUGIN Uncanny Automator

CVE-2026-15008

HIGH CVSS 8.1 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-13741 - Wordpress Mobile Number Signup And Login Plugin

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator by submitting a forged `digits_reg_userrole` value during profile update, granted the site administrator has configured the built-in DIGITS User Role field.

PLUGIN Wordpress Mobile Number Signup And Login

CVE-2026-13741

HIGH CVSS 8.8 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12585 - Abandoned Cart Lite For Woocommerce Plugin

The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled.

PLUGIN Abandoned Cart Lite For Woocommerce

CVE-2026-12585

HIGH CVSS 8.1 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12978 - Before 3 Plugin

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered when the Divi /builder is active.

PLUGIN Before 3

CVE-2026-12978

HIGH CVSS 7.1 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12525 - Redux Framework Plugin

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled.

PLUGIN Redux Framework

CVE-2026-12525

HIGH CVSS 8.8 2026-07-16
Threat Entry Updated 2026-07-18

CVE-2026-13042 - Rpb Chessboard Plugin

The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's save-time kses sanitization does not mitigate this issue because the crafted payload uses only kses-allowed tags and attributes (such as an <a> element with title and href), and the dangerous attribute-breaking HTML is synthesized…

PLUGIN Rpb Chessboard

CVE-2026-13042

HIGH CVSS 7.2 2026-07-16
Threat Entry Updated 2026-07-18

CVE-2026-12753 - Th Advance Product Search Plugin

The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Th Advance Product Search

CVE-2026-12753

HIGH CVSS 7.5 2026-07-16
Threat Entry Updated 2026-07-15

CVE-2026-12997 - Gravity Forms Plugin

The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the targeted form to not enforce login (so publicly accessible), which allows the unauthenticated attacker to reach the process_send_resume_link endpoint and supply an arbitrary recipient email address to receive the traversal-retrieved file as a notification attachment.

PLUGIN Gravity Forms

CVE-2026-12997

HIGH CVSS 7.5 2026-07-15
Threat Entry Updated 2026-07-15

CVE-2026-12512 - Quotes Llama Plugin

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform UNION-based SQL injection and read arbitrary data from the database, including password hashes.

PLUGIN Quotes Llama

CVE-2026-12512

HIGH CVSS 8.6 2026-07-15
Threat Entry Updated 2026-07-15

CVE-2026-12281 - Before 2 Plugin

The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an unauthenticated attacker can log in with forged identity headers and, when automatic account creation and the default administrator role mapping are enabled, create and sign in as a new administrator. Exploitation requires the non-default HTTP header attribute mode, an empty or absent spoof…

PLUGIN Before 2

CVE-2026-12281

HIGH CVSS 8.1 2026-07-15
Threat Entry Updated 2026-07-14

CVE-2026-12583 - Via A Property Oriented Gadget Chain Bundled With The Newsletters Plugin

The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and execute code on the server.

PLUGIN Via A Property Oriented Gadget Chain Bundled With The Newsletters

CVE-2026-12583

HIGH CVSS 8.1 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-12511 - Ai Engine Plugin

The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.

PLUGIN Ai Engine

CVE-2026-12511

HIGH CVSS 8.1 2026-07-14
Threat Entry Updated 2026-07-13

CVE-2026-61955 - WordPress component Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through

PLUGIN WordPress component

CVE-2026-61955

HIGH CVSS 7.6 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-59521 - Real Testimonials Plugin

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through

PLUGIN Real Testimonials

CVE-2026-59521

HIGH CVSS 7.2 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61956 - ووسلام – همگام سازی ووکامرس و باسلام Plugin

Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام – همگام سازی ووکامرس و باسلام: from n/a through

PLUGIN ووسلام – همگام سازی ووکامرس و باسلام

CVE-2026-61956

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57815 - Forminator Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Path Traversal.This issue affects Forminator: from n/a through

PLUGIN Forminator

CVE-2026-57815

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-59516 - ICS Calendar Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through

PLUGIN ICS Calendar

CVE-2026-59516

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57816 - Funnel Builder by FunnelKit Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows Reflected XSS.This issue affects Funnel Builder by FunnelKit: from n/a through

PLUGIN Funnel Builder by FunnelKit

CVE-2026-57816

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57814 - Forminator Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows DOM-Based XSS.This issue affects Forminator: from n/a through

PLUGIN Forminator

CVE-2026-57814

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57810 - APIExperts Square for WooCommerce Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through

PLUGIN APIExperts Square for WooCommerce

CVE-2026-57810

HIGH CVSS 8.5 2026-07-13
Scroll to top