Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 1-20 of 12246 records
Threat Entry Updated 2026-07-21

CVE-2026-65051 - Ninja Forms Plugin

Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a malicious AJAX submission overriding field types, removing required flags, and disabling CAPTCHA checks through the nopriv AJAX endpoint to trigger form actions such as email notifications and database storage with unverified, attacker-controlled content.

PLUGIN Ninja Forms

CVE-2026-65051

MEDIUM CVSS 6.9 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-15145 - Essential Addons For Elementor Lite Plugin

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor Lite

CVE-2026-15145

MEDIUM CVSS 6.4 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-1372 - Tutor Lms Elementor Addons Plugin

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization.

PLUGIN Tutor Lms Elementor Addons

CVE-2026-1372

MEDIUM CVSS 4.3 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-14185 - Allowing Authenticated Users With Subscriber Level Access To Modify The Wpbot Plugin

The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's configuration.

PLUGIN Allowing Authenticated Users With Subscriber Level Access To Modify The Wpbot

CVE-2026-14185

MEDIUM CVSS 4.3 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-15782 - Wpforms Lite Plugin

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the OptinMonster plugin to be installed and configured…

PLUGIN Wpforms Lite

CVE-2026-15782

MEDIUM CVSS 4.9 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-15156 - Essential Addons For Elementor Lite Plugin

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor Lite

CVE-2026-15156

MEDIUM CVSS 6.4 2026-07-21
Threat Entry Updated 2026-07-20

CVE-2026-12900 - Ultimate Addons For Gutenberg Plugin

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Addons For Gutenberg

CVE-2026-12900

MEDIUM CVSS 6.4 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-8825 - Elementor Website Builder Plugin

The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).

PLUGIN Elementor Website Builder

CVE-2026-8825

MEDIUM CVSS 4.9 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12973 - Payplus Payment Gateway Plugin

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.

PLUGIN Payplus Payment Gateway

CVE-2026-12973

MEDIUM CVSS 6.5 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12898 - All In One Wp Migration And Backup Plugin

The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory.

PLUGIN All In One Wp Migration And Backup

CVE-2026-12898

MEDIUM CVSS 6.5 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-13432 - Ticated Users With Subscriber Level Access Or Higher To Deactivate The Thumbpress Plugin

The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling functionality.

PLUGIN Ticated Users With Subscriber Level Access Or Higher To Deactivate The Thumbpress

CVE-2026-13432

MEDIUM CVSS 5.4 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-13156 - A Logged In Administrator Into Visiting A Crafted Page That Wipes The Mailersend Plugin

The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.

PLUGIN A Logged In Administrator Into Visiting A Crafted Page That Wipes The Mailersend

CVE-2026-13156

MEDIUM CVSS 5.4 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12972 - Payplus Payment Gateway Plugin

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.

PLUGIN Payplus Payment Gateway

CVE-2026-12972

MEDIUM CVSS 5.3 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12723 - Before 6 Plugin

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.

PLUGIN Before 6

CVE-2026-12723

MEDIUM CVSS 5.3 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-11868 - Wp Travel Plugin

The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

PLUGIN Wp Travel

CVE-2026-11868

MEDIUM CVSS 5.3 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-10724 - Reviews Feed Plugin

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.

PLUGIN Reviews Feed

CVE-2026-10724

MEDIUM CVSS 4.8 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12724 - Before 6 Plugin

The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing.

PLUGIN Before 6

CVE-2026-12724

MEDIUM CVSS 4.3 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-57857 - Flow Payment Plugin

The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an order cancellation, the error_message GET parameter is passed directly to wc_add_notice() in flowpayment-fl.php (lines 57-58) without input sanitization (for example sanitize_text_field()) or output escaping (for example esc_html()) before being rendered in the checkout notice HTML. An unauthenticated attacker can craft a URL containing a JavaScript payload in the error_message parameter (for example /checkout/?add-to-cart={product-id}&cancel_order=true&error_message={payload}); when a victim with an active WooCommerce checkout session follows the link,…

PLUGIN Flow Payment

CVE-2026-57857

MEDIUM CVSS 5.1 2026-07-18
Threat Entry Updated 2026-07-20

CVE-2026-9734 - W3sc Elementor To Zoho Plugin

The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possible for unauthenticated attackers to modify the plugin's Zoho CRM integration settings, replacing the configured data center, client ID, client secret, and user email credentials with attacker-controlled values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN W3sc Elementor To Zoho

CVE-2026-9734

MEDIUM CVSS 4.3 2026-07-18
Threat Entry Updated 2026-07-17

CVE-2026-9656 - Leadin Plugin

The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the site's plaintext HubSpot OAuth refresh token exposed via the window.leadinConfig JavaScript object, which can then be used to access or modify data in the connected HubSpot tenant. Although the refresh token is stored at rest with AES-256-CTR encryption, decryption occurs server-side before…

PLUGIN Leadin

CVE-2026-9656

MEDIUM CVSS 4.3 2026-07-17
Scroll to top