sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total279
Critical0
High0
Medium0
Reset
Showing 1-20 of 279 records
Threat Entry Updated 2026-09-04

Directorist - Security Vulnerability (CVE-2026-84066)

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.

PLUGIN Directorist

CVE-2026-84066

LOW CVSS 3.1 2026-09-04
Threat Entry Updated 2026-09-03

Timetics - Security Vulnerability (CVE-2026-14326)

The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.

PLUGIN Timetics

CVE-2026-14326

LOW CVSS 3.8 2026-09-02
Threat Entry Updated 2026-09-03

GutenKit - Security Vulnerability (CVE-2026-19698)

The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into pages served to other users and to anonymous visitors. JavaScript execution is not possible at that role, so the impact is limited to defacement, interface redressing and forcing external resources to load.

PLUGIN GutenKit

CVE-2026-19698

LOW CVSS 3.5 2026-09-02
Threat Entry Updated 2026-09-03

MasterStudy LMS WordPress Plugin - Security Vulnerability (CVE-2026-81198)

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors.

PLUGIN MasterStudy LMS WordPress Plugin

CVE-2026-81198

LOW CVSS 3.8 2026-09-02
Threat Entry Updated 2026-09-03

Rank Math SEO - Security Vulnerability (CVE-2026-77783)

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts.

PLUGIN Rank Math SEO

CVE-2026-77783

LOW CVSS 3.7 2026-09-02
Threat Entry Updated 2026-09-03

Rank Math SEO - Security Vulnerability (CVE-2026-77787)

The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users.

PLUGIN Rank Math SEO

CVE-2026-77787

LOW CVSS 2.7 2026-09-02
Threat Entry Updated 2026-09-03

Rank Math SEO - Security Vulnerability (CVE-2026-77785)

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning its content and SEO metadata, allowing users with the Author role and above to read the title, body and metadata of other users' non-public posts.

PLUGIN Rank Math SEO

CVE-2026-77785

LOW CVSS 2.7 2026-09-02
Threat Entry Updated 2026-09-03

Rank Math SEO - Security Vulnerability (CVE-2026-77784)

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allowing users with the Author role and above to alter that metadata on content, taxonomy terms and user profiles they do not own, and to remove other users' content from the site's sitemap and search engine index.

PLUGIN Rank Math SEO

CVE-2026-77784

LOW CVSS 2.7 2026-09-02
Threat Entry Updated 2026-08-31

MW WP Form - Cross-Site Scripting (XSS) (CVE-2026-78364)

The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.

PLUGIN MW WP Form

CVE-2026-78364

LOW CVSS 3.5 2026-08-30
Threat Entry Updated 2026-08-31

MasterStudy LMS WordPress Plugin - Security Vulnerability (CVE-2026-81200)

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs.

PLUGIN MasterStudy LMS WordPress Plugin

CVE-2026-81200

LOW CVSS 2.7 2026-08-29
Threat Entry Updated 2026-08-31

Booking for Appointments and Events Calendar - Broken Access Control (CVE-2026-77704)

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment.

PLUGIN Booking for Appointments and Events Calendar

CVE-2026-77704

LOW CVSS 2.7 2026-08-29
Threat Entry Updated 2026-08-28

Quiz and Survey Master - Security Vulnerability (CVE-2026-79615)

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.

PLUGIN Quiz and Survey Master

CVE-2026-79615

LOW CVSS 2.7 2026-08-28
Threat Entry Updated 2026-08-28

When The Administrator Has Granted The Editor Role Access To The Cmp - Cross-Site Scripting (XSS) (CVE-2026-13416)

The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.

PLUGIN When The Administrator Has Granted The Editor Role Access To The Cmp

CVE-2026-13416

LOW CVSS 3.5 2026-08-27
Threat Entry Updated 2026-08-26

Forminator Forms - Security Vulnerability (CVE-2026-19220)

The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.

PLUGIN Forminator Forms

CVE-2026-19220

LOW CVSS 3.7 2026-08-26
Threat Entry Updated 2026-08-26

Content Mask - Broken Access Control (CVE-2026-77003)

The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability.

PLUGIN Content Mask

CVE-2026-77003

LOW CVSS 2.7 2026-08-23
Threat Entry Updated 2026-08-26

Tutor Lms - Security Vulnerability (CVE-2026-14187)

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.

PLUGIN Tutor Lms

CVE-2026-14187

LOW CVSS 2.7 2026-08-22
Threat Entry Updated 2026-08-26

Limit Login Attempts Reloaded - Security Vulnerability (CVE-2026-18356)

The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.

PLUGIN Limit Login Attempts Reloaded

CVE-2026-18356

LOW CVSS 3.7 2026-08-21
Threat Entry Updated 2026-08-26

Eventin - Improper Input Validation (CVE-2026-13176)

The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts.

PLUGIN Eventin

CVE-2026-13176

LOW CVSS 2.7 2026-08-21
Threat Entry Updated 2026-08-26

Duplicate Post - Broken Access Control (CVE-2026-19435)

The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.

PLUGIN Duplicate Post

CVE-2026-19435

LOW CVSS 2.7 2026-08-21