Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4,286
Critical0
High4,286
Medium0
Reset
Showing 121-140 of 4286 records
Threat Entry Updated 2026-07-13

CVE-2026-12275 - Tutor Lms Plugin

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.

PLUGIN Tutor Lms

CVE-2026-12275

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-1359 - Ai Image Ai Video Generation Plugin

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.

PLUGIN Ai Image Ai Video Generation

CVE-2026-1359

HIGH CVSS 8.8 2026-07-11
Threat Entry Updated 2026-07-14

CVE-2026-9282 - W3 Total Cache Plugin

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources().

PLUGIN W3 Total Cache

CVE-2026-9282

HIGH CVSS 7.5 2026-07-11
Threat Entry Updated 2026-07-15

CVE-2026-15155 - Essential Addons For Elementor Lite Plugin

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct outgoing email headers — the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail…

PLUGIN Essential Addons For Elementor Lite

CVE-2026-15155

HIGH CVSS 8.8 2026-07-11
Threat Entry Updated 2026-07-13

CVE-2026-4661 - Easy Sticky Sidebar Plugin

The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in all versions up to, and including, 2.2.2. This is due to insufficient escaping of user-supplied column names in the ajaxCheck() method and lack of preparation in the $wpdb->update() call. The vulnerability is compounded by the complete absence of authorization checks and the endpoint being registered for unauthenticated users via wp_ajax_nopriv_. This makes it possible for unauthenticated attackers to inject arbitrary SQL queries and extract…

PLUGIN Easy Sticky Sidebar

CVE-2026-4661

HIGH CVSS 7.5 2026-07-11
Threat Entry Updated 2026-07-13

CVE-2026-6939 - Corvuspay Woocommerce Integration Plugin

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The unauthenticated REST endpoint POST /wp-json/corvuspay/success/ is registered with permission_callback set to __return_true, and although a signature validation step exists it only logs the result without halting execution, meaning an attacker can…

PLUGIN Corvuspay Woocommerce Integration

CVE-2026-6939

HIGH CVSS 7.2 2026-07-11
Threat Entry Updated 2026-07-15

CVE-2026-7655 - SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments Plugin

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user's password and gain access to their account if the customer ID…

PLUGIN SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments

CVE-2026-7655

HIGH CVSS 8.1 2026-07-11
Threat Entry Updated 2026-07-13

CVE-2026-13378 - Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database Plugin

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database

CVE-2026-13378

HIGH CVSS 7.2 2026-07-11
Threat Entry Updated 2026-07-13

CVE-2026-3576 - Planyo Online Reservation System Plugin

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. The send_http_post() function validates the host of the provided URL against an allowlist that includes 'localhost', but critically fails to validate the URL scheme/protocol. This makes it possible for unauthenticated attackers to supply a file:// URL (e.g., file://localhost/etc/passwd) which bypasses the host allowlist check because…

PLUGIN Planyo Online Reservation System

CVE-2026-3576

HIGH CVSS 7.2 2026-07-11
Threat Entry Updated 2026-07-13

CVE-2026-2354 - Swiss Toolkit For Wp Plugin

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extension_files()` function hooks into WordPress's `wp_check_filetype_and_ext` filter and uses `strpos()` to check if a filename contains a configured extension string, rather than verifying the actual file extension. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files (including PHP) on the affected site's server which may make remote code…

PLUGIN Swiss Toolkit For Wp

CVE-2026-2354

HIGH CVSS 8.8 2026-07-11
Threat Entry Updated 2026-07-13

CVE-2026-14262 - Simple JWT Login – Allows you to use JWT on REST endpoints. Plugin

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` only overwrites JWT payload keys whose names appear in the admin-configured `jwt_payload` list — leaving any attacker-supplied identity claims such as `email`, `id`, or `username` intact and signed into the JWT with the site's HS256 secret. This makes it possible for authenticated attackers, with subscriber-level access and above, to…

PLUGIN Simple JWT Login – Allows you to use JWT on REST endpoints.

CVE-2026-14262

HIGH CVSS 8.8 2026-07-11
Threat Entry Updated 2026-07-14

CVE-2026-15335 - Booking Package Plugin

The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable REST API endpoint /wp-json/booking-package/v1/request is registered with permission_callback: __return_true and wp_magic_quotes does not apply to REST-sourced $_POST…

PLUGIN Booking Package

CVE-2026-15335

HIGH CVSS 7.5 2026-07-11
Threat Entry Updated 2026-07-14

CVE-2026-15338 - La Studio Element Kit For Elementor Plugin

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The wp_normalize_path function used in…

PLUGIN La Studio Element Kit For Elementor

CVE-2026-15338

HIGH CVSS 7.5 2026-07-11
Threat Entry Updated 2026-07-13

CVE-2026-13353 - WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel Plugin

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and StartImport, combined with the plugin nonce being exposed to any authenticated user who can load an admin page, allowing a Subscriber to install the Import WooCommerce add-on, persist attacker-controlled PHP expressions in the MappedFields parameter, and trigger evaluation via…

PLUGIN WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

CVE-2026-13353

HIGH CVSS 8.8 2026-07-11
Threat Entry Updated 2026-07-13

CVE-2026-13114 - Motors – Car Dealership & Classified Listings Plugin

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Motors – Car Dealership & Classified Listings Plugin

CVE-2026-13114

HIGH CVSS 7.2 2026-07-11
Threat Entry Updated 2026-07-13

CVE-2026-13756 - Wp Grid Builder Plugin

The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metadata` REST endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to Administrator by updating their own `wp_capabilities` user meta with a crafted nested array payload.

PLUGIN Wp Grid Builder

CVE-2026-13756

HIGH CVSS 8.8 2026-07-11
Threat Entry Updated 2026-07-10

CVE-2026-1667 - GEO Plugin by Squirrly SEO

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, and including, 14.0.0 due to a leak of an API token and insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to create arbitrary posts, and, if the Advanced Custom Fields plugin is installed and activated, inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN GEO Plugin by Squirrly SEO

CVE-2026-1667

HIGH CVSS 7.2 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-13347 - Hide Wp Login Plugin

The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrapper_css query parameters processed by the elementor_assets_filter() function. This is due to the function concatenating user-supplied input directly onto ABSPATH and passing the result to file_get_contents() without any path traversal validation, allow-list, realpath containment, or extension check; the result is then echoed in the HTTP response. Although the output is passed through wp_kses_post(), that function only filters HTML tags and does not prevent disclosure of…

PLUGIN Hide Wp Login

CVE-2026-13347

HIGH CVSS 7.5 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-12685 - Escortwp Escortwp Theme

The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly transmits the site URL, administrator email address, and license key to a third-party server.

THEME Escortwp Escortwp

CVE-2026-12685

HIGH CVSS 7.5 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15298 - TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot Plugin

The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including, 1.14.14. This is due to insufficient input sanitization when processing Telegram API responses containing attacker-controlled chat titles. This makes it possible for unauthenticated attackers to inject malicious scripts via Telegram chat titles that execute when an administrator opens the TelSender settings page and clicks the "Tested" button.

PLUGIN TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot

CVE-2026-15298

HIGH CVSS 7.2 2026-07-10
Scroll to top