Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,625
Critical0
High3,625
Medium0
Reset
Showing 81-100 of 3625 records
Threat Entry Updated 2026-05-14

CVE-2026-6514 - Infusedwoo Pro Plugin

The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Infusedwoo Pro

CVE-2026-6514

HIGH CVSS 7.5 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-6506 - Infusedwoo Pro Plugin

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization and capability checks, as well as lacking restrictions on which user meta keys can be updated. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their own wp_capabilities user meta to grant themselves Administrator role privileges.

PLUGIN Infusedwoo Pro

CVE-2026-6506

HIGH CVSS 8.8 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-5395 - Conversational Form Builder Plugin

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Fluent Forms manager-level access and above, to bypass form-level access restrictions to access submissions from forms they are not authorized to view, export data from arbitrary database tables, and enumerate database table names via error message disclosure.

PLUGIN Conversational Form Builder

CVE-2026-5395

HIGH CVSS 8.2 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-3892 - Classified Listings Plugin

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo upload flow. The plugin allows any authenticated user to set an arbitrary filesystem path via the profile update handler. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server.

PLUGIN Classified Listings

CVE-2026-3892

HIGH CVSS 8.1 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-3718 - Managewp Worker Plugin

The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP request header in all versions up to, and including, 4.9.31. This is due to insufficient input sanitization and output escaping of attacker-controlled header values. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator visits the plugin's connection management page with debug parameters.

PLUGIN Managewp Worker

CVE-2026-3718

HIGH CVSS 7.2 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-5396 - Fluent Forms Plugin

The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based on a user-supplied `form_id` query parameter. This makes it possible for authenticated attackers, with Fluent Forms Manager access restricted to specific forms, to read, modify status, add notes to, and permanently delete form submissions belonging to any other form by spoofing the form_id parameter to a form they are authorized for.

PLUGIN Fluent Forms

CVE-2026-5396

HIGH CVSS 8.2 2026-05-14
Threat Entry Updated 2026-05-13

CVE-2026-4609 - Profilegrid User Profiles Groups And Communities Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add themselves or any registered user to any ProfileGrid group, including closed and paid groups, bypassing all authorization and payment gates.

PLUGIN Profilegrid User Profiles Groups And Communities

CVE-2026-4609

HIGH CVSS 7.1 2026-05-13
Threat Entry Updated 2026-05-13

CVE-2026-6177 - Custom Twitter Feeds Plugin

The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's ctf_get_more_posts AJAX action is available to unauthenticated users and directly outputs cached tweet data through nl2br() without HTML escaping. When an attacker can get malicious content into cached tweet data (either by tweeting content that gets cached by the site's feed configuration, or through other vulnerabilities), the malicious HTML/JavaScript is executed when…

PLUGIN Custom Twitter Feeds

CVE-2026-6177

HIGH CVSS 7.2 2026-05-13
Threat Entry Updated 2026-05-13

CVE-2026-3425 - Rometheme For Elementor Plugin

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter of the 'get_content' AJAX action. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included.

PLUGIN Rometheme For Elementor

CVE-2026-3425

HIGH CVSS 8.8 2026-05-13
Threat Entry Updated 2026-05-13

CVE-2026-4798 - Avada Builder Plugin

The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note: The vulnerability can only be exploited if WooCommerce was previously used and then deactivated.

PLUGIN Avada Builder

CVE-2026-4798

HIGH CVSS 7.5 2026-05-13
Threat Entry Updated 2026-05-13

CVE-2026-6929 - Joomsport Sports League Results Management Plugin

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' parameter in all versions up to, and including, 5.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Joomsport Sports League Results Management

CVE-2026-6929

HIGH CVSS 7.5 2026-05-13
Threat Entry Updated 2026-05-13

CVE-2026-7635 - Coreactivity Plugin

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or strip PHP serialization syntax from the User-Agent HTTP header before storing it in the logmeta table, and subsequently calling `maybe_unserialize()` on every retrieved `meta_value` in `query_metas()` without verifying the data was originally serialized by the application. This makes it possible for unauthenticated attackers to inject a crafted PHP serialized payload via the User-Agent header during any logged…

PLUGIN Coreactivity

CVE-2026-7635

HIGH CVSS 8.1 2026-05-13
Threat Entry Updated 2026-05-13

CVE-2026-5371 - Google Analytics For Wordpress Plugin

The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability checks on the get_ads_access_token() and reset_experience() functions in all versions up to, and including, 10.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve live Google OAuth access tokens and reset Plugins's Google Ads integration.

PLUGIN Google Analytics For Wordpress

CVE-2026-5371

HIGH CVSS 7.1 2026-05-12
Threat Entry Updated 2026-05-13

CVE-2026-1250 - Court Reservation Plugin

The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.10.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Court Reservation

CVE-2026-1250

HIGH CVSS 7.5 2026-05-12
Threat Entry Updated 2026-05-12

CVE-2026-45218 - WP Travel Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows Blind SQL Injection.This issue affects WP Travel: from n/a through

PLUGIN WP Travel

CVE-2026-45218

HIGH CVSS 7.7 2026-05-12
Threat Entry Updated 2026-05-12

CVE-2026-45214 - Elementor Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Blind SQL Injection.This issue affects Xpro Elementor Addons: from n/a through

PLUGIN Elementor

CVE-2026-45214

HIGH CVSS 8.5 2026-05-12
Threat Entry Updated 2026-05-12

CVE-2026-45211 - APIExperts Square for WooCommerce Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through

PLUGIN APIExperts Square for WooCommerce

CVE-2026-45211

HIGH CVSS 8.5 2026-05-12
Threat Entry Updated 2026-05-12

CVE-2026-42742 - WPForms Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite allows Blind SQL Injection.This issue affects Views for WPForms: from n/a through

PLUGIN WPForms

CVE-2026-42742

HIGH CVSS 8.5 2026-05-12
Threat Entry Updated 2026-05-12

CVE-2026-42741 - Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend views-for-ninja-forms allows Blind SQL Injection.This issue affects Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend: from n/a through

PLUGIN Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend

CVE-2026-42741

HIGH CVSS 8.5 2026-05-12
Threat Entry Updated 2026-05-12

CVE-2026-45213 - BEAR Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQL Injection.This issue affects BEAR: from n/a through

PLUGIN BEAR

CVE-2026-45213

HIGH CVSS 7.6 2026-05-12
Scroll to top