Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total215
Critical0
High0
Medium0
Reset
Showing 1-20 of 215 records
Threat Entry Updated 2026-07-20

CVE-2026-10755 - All In One Seo Plugin

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

PLUGIN All In One Seo

CVE-2026-10755

LOW CVSS 2.7 2026-07-20
Threat Entry Updated 2026-07-16

CVE-2026-12907 - Before 2 Plugin

The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, footer or other global areas displayed to all visitors, which is normally restricted to administrators.

PLUGIN Before 2

CVE-2026-12907

LOW CVSS 2.7 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12906 - Before 2 Plugin

The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private, draft, pending, scheduled and trashed posts.

PLUGIN Before 2

CVE-2026-12906

LOW CVSS 2.7 2026-07-16
Threat Entry Updated 2026-07-13

CVE-2026-61971 - User Profile Picture Plugin

Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through

PLUGIN User Profile Picture

CVE-2026-61971

LOW CVSS 2.7 2026-07-13
Threat Entry Updated 2026-07-02

CVE-2026-11781 - S Adminify Plugin

The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by one of its administration search features, allowing users with a low-privilege role (Contributor) to disclose non-public content that WordPress would not otherwise expose to them, such as other authors' unpublished post titles, pending comment content, the site's Adminify WordPress plugin before 4.2.10 inventory, and user account names.

PLUGIN S Adminify

CVE-2026-11781

LOW CVSS 2.7 2026-07-02
Threat Entry Updated 2026-07-02

CVE-2026-11578 - Fluent Forms Plugin

The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default configuration in which an administrator has created at least one Manager restricted to specific forms.

PLUGIN Fluent Forms

CVE-2026-11578

LOW CVSS 2.7 2026-07-02
Threat Entry Updated 2026-07-01

CVE-2026-11880 - Fluent Forms Plugin

The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.

PLUGIN Fluent Forms

CVE-2026-11880

LOW CVSS 3.1 2026-07-01
Threat Entry Updated 2026-06-25

CVE-2026-10753 - Site Kit By Google Plugin

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing access (such as Editors) to modify a site-wide Site Kit by Google WordPress plugin before 1.176.0 setting that should only be modifiable by administrators.

PLUGIN Site Kit By Google

CVE-2026-10753

LOW CVSS 2.7 2026-06-24
Threat Entry Updated 2026-06-18

CVE-2026-12102 - Members Directory Plugin For Wp

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with editor-level access and above, to reset and permanently delete the avatar or banner image of any arbitrary user, including administrators, by clearing their avatar_thumb or banner_thumb metadata in the uwp_usermeta table.

PLUGIN Members Directory Plugin For Wp

CVE-2026-12102

LOW CVSS 2.7 2026-06-18
Threat Entry Updated 2026-06-17

CVE-2026-9061 - Store Locator Plugin

The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin before 1.6.9 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).

PLUGIN Store Locator

CVE-2026-9061

LOW CVSS 3.5 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9062 - Store Locator Plugin

The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.

PLUGIN Store Locator

CVE-2026-9062

LOW CVSS 3.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9269 - Secure Copy Content Protection And Content Locking Plugin

The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Secure Copy Content Protection And Content Locking

CVE-2026-9269

LOW CVSS 3.5 2026-06-12
Threat Entry Updated 2026-06-17

CVE-2026-9060 - Store Locator Plugin

The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network where the super admin visits the page).

PLUGIN Store Locator

CVE-2026-9060

LOW CVSS 3.5 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-8981 - Custom Block Builder Plugin

The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary JavaScript that executes for any visitor of pages embedding the affected block.

PLUGIN Custom Block Builder

CVE-2026-8981

LOW CVSS 3.5 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-4512 - Recaptcha By Webdesignby Plugin

The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript string context via the grecaptcha_js() function. This allows administrators on multisite installations (who do not have the unfiltered_html capability) to inject arbitrary JavaScript that executes for all visitors to the WordPress login page.

PLUGIN Recaptcha By Webdesignby

CVE-2026-4512

LOW CVSS 3.5 2026-04-23
Threat Entry Updated 2026-06-17

CVE-2026-3155 - Web Push Notifications Plugin

The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete OneSignal metadata for arbitrary posts.

PLUGIN Web Push Notifications

CVE-2026-3155

LOW CVSS 3.1 2026-04-16
Threat Entry Updated 2026-06-17

CVE-2026-39510 - Image Photo Gallery Final Tiles Grid Plugin

Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through

PLUGIN Image Photo Gallery Final Tiles Grid

CVE-2026-39510

LOW CVSS 2.7 2026-04-08
Threat Entry Updated 2026-06-17

CVE-2026-3339 - Keep Backup Daily Plugin

The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and including, 2.1.1 via the `kbd_open_upload_dir` AJAX action. This is due to insufficient validation of the `kbd_path` parameter, which is only sanitized with `sanitize_text_field()` - a function that does not strip path traversal sequences. This makes it possible for authenticated attackers, with Administrator-level access and above, to list the contents of arbitrary directories on the server outside of the intended uploads directory.

PLUGIN Keep Backup Daily

CVE-2026-3339

LOW CVSS 2.7 2026-03-21
Threat Entry Updated 2026-06-17

CVE-2026-32445 - Elementor Plugin

Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through

PLUGIN Elementor

CVE-2026-32445

LOW CVSS 2.7 2026-03-13
Scroll to top