Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4,286
Critical0
High4,286
Medium0
Reset
Showing 161-180 of 4286 records
Threat Entry Updated 2026-07-08

CVE-2026-6854 - My Calendar – Accessible Event Manager Plugin

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN My Calendar – Accessible Event Manager

CVE-2026-6854

HIGH CVSS 7.5 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6818 - VikBooking Hotel Booking Engine & PMS Plugin

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN VikBooking Hotel Booking Engine & PMS

CVE-2026-6818

HIGH CVSS 7.2 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-3688 - WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Plugin

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.

PLUGIN WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

CVE-2026-3688

HIGH CVSS 8.1 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6230 - Tainacan Plugin

The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Tainacan

CVE-2026-6230

HIGH CVSS 7.5 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12378 - Appointment Booking Calendar Plugin and Scheduling Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.

PLUGIN Appointment Booking Calendar Plugin and Scheduling Plugin

CVE-2026-12378

HIGH CVSS 8.1 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-9700 - Eventer Plugin

The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Eventer

CVE-2026-9700

HIGH CVSS 7.5 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14495 - Dologin Security Plugin

The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4.3. The vulnerability exists because `dologin\s::rrand()` seeds the Mersenne Twister with `mt_srand((double) microtime() * 1000000)` — discarding the integer-seconds component of `microtime()` and constraining the seed to a range of approximately 10^6 values (~20 bits of entropy) — after which every character of the 32-character magic-link token is drawn sequentially with `mt_rand()`, making the entire token a deterministic function of that seed. Because `Pswdless::try_login()` is registered on the unauthenticated…

PLUGIN Dologin Security

CVE-2026-14495

HIGH CVSS 8.8 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14489 - Whmcs Bridge Plugin

The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Whmcs Bridge

CVE-2026-14489

HIGH CVSS 8.8 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-9842 - Backstage – Customizer Demo Access Plugin

The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to the plugin assigning the `manage_options` capability to the `backstage_customizer_user` demo role, which is more permissive than necessary for Customizer-only demo access. This makes it possible for unauthenticated attackers to navigate beyond the Customizer and update arbitrary WordPress options such as `default_role`, leading to privilege escalation.

PLUGIN Backstage – Customizer Demo Access

CVE-2026-9842

HIGH CVSS 7.5 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14482 - Duoshuo Plugin

The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The vulnerability exists due to a missing capability and nonce check on a directly web-accessible API endpoint, combined with a trivially forgeable HMAC-SHA1 signature keyed on an always-empty WordPress option, which allows the endpoint's `update_option` handler to pass attacker-controlled `option` and `value` parameters directly to WordPress's `update_option` function without any allowlist or sanitization. This makes it possible for unauthenticated attackers to update arbitrary WordPress options — such as setting `default_role` to `administrator`…

PLUGIN Duoshuo

CVE-2026-14482

HIGH CVSS 8.8 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14158 - Widget Logic Visual Plugin

The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_visual_check_visibility function. This is due to missing capability check and nonce verification on the widget-logic-update-conditional-tags AJAX action combined with insufficient sanitization of the 'nwlv[cod-tag]' parameter before storage and subsequent use in an eval() call. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server.

PLUGIN Widget Logic Visual

CVE-2026-14158

HIGH CVSS 8.8 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14244 - Jssor Slider by jssor.com Plugin

The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.1.24 via the 'url' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Jssor Slider by jssor.com

CVE-2026-14244

HIGH CVSS 7.5 2026-07-08
Threat Entry Updated 2026-07-07

CVE-2026-6101 - Accelerated Mobile Pages Plugin

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined with inadequate cleanup that fails to remove nested directories and files. This makes it possible for authenticated attackers, with Author-level access and above, and permissions granted by an Administrator, to write arbitrary files to the server in a web-accessible location, potentially leading to remote code execution on hosts that execute PHP files in…

PLUGIN Accelerated Mobile Pages

CVE-2026-6101

HIGH CVSS 7.5 2026-07-07
Threat Entry Updated 2026-07-07

CVE-2026-12277 - Frontend File Manager Plugin

The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the site into its setup routine, which can be leveraged toward a full site takeover.

PLUGIN Frontend File Manager Plugin

CVE-2026-12277

HIGH CVSS 8.7 2026-07-07
Threat Entry Updated 2026-07-06

CVE-2026-11962 - Before 1 Plugin

The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management operations, allowing authenticated users who have been granted file-manager access — which its premium add-on can extend to sub-administrator roles — to upload arbitrary PHP files and achieve remote code execution. This is an incomplete fix of CVE-2024-7985, which only added file-type validation to the upload operation.

PLUGIN Before 1

CVE-2026-11962

HIGH CVSS 8.8 2026-07-06
Threat Entry Updated 2026-07-06

CVE-2026-11855 - Simple Membership Plugin

The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in the context of a logged-in administrator.

PLUGIN Simple Membership

CVE-2026-11855

HIGH CVSS 8.8 2026-07-06
Threat Entry Updated 2026-07-06

CVE-2026-12083 - Admin Site Enhancements Pro Plugin

The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account back to the administrator role. This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordPress role API exposes.

PLUGIN Admin Site Enhancements Pro

CVE-2026-12083

HIGH CVSS 8.1 2026-07-06
Threat Entry Updated 2026-07-06

CVE-2026-11766 - Ultimate Member Plugin

The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript that executes when any user, including an administrator, views the affected profile.

PLUGIN Ultimate Member

CVE-2026-11766

HIGH CVSS 8.0 2026-07-06
Threat Entry Updated 2026-07-06

CVE-2026-10830 - Before 1 Plugin

The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registration endpoint is not already associated with an existing user before overwriting that user's password, allowing unauthenticated attackers to reset the password of arbitrary accounts, including administrators, and take over the site.

PLUGIN Before 1

CVE-2026-10830

HIGH CVSS 8.8 2026-07-06
Threat Entry Updated 2026-07-06

CVE-2026-9148 - Comments – wpDiscuz Plugin

The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the stored comment_author_url value directly into single-quoted HTML attributes without applying esc_url() or esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Comments – wpDiscuz

CVE-2026-9148

HIGH CVSS 7.2 2026-07-03
Scroll to top