Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total11,547
Critical0
High0
Medium11,547
Reset
Showing 181-200 of 11547 records
Threat Entry Updated 2026-05-20

CVE-2026-6400 - Child Height Predictor Plugin

The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is due to missing nonce verification in the options() function, which handles plugin settings updates. The form template does not include a wp_nonce_field() call, and the handler never calls check_admin_referer() or wp_verify_nonce(). This makes it possible for unauthenticated attackers to trick a site administrator into clicking a link or visiting a malicious page that submits a forged POST request, causing unauthorized changes to the plugin settings…

PLUGIN Child Height Predictor

CVE-2026-6400

MEDIUM CVSS 4.3 2026-05-20
Threat Entry Updated 2026-05-20

CVE-2026-6072 - Oliver POS – A WooCommerce Point of Sale (POS) Plugin

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.4.2.6. The plugin protects its entire /wp-json/pos-bridge/* REST API namespace through the oliver_pos_rest_authentication() permission callback, which uses a loose PHP comparison (==) to compare the attacker-supplied 'OliverAuth' header value against the 'oliver_pos_authorization_token' option. On fresh installations where the admin has not yet completed the connection flow, this option is unset (get_option returns false). Due to PHP's type juggling, the loose comparison '0'…

PLUGIN Oliver POS – A WooCommerce Point of Sale (POS)

CVE-2026-6072

MEDIUM CVSS 6.5 2026-05-20
Threat Entry Updated 2026-05-20

CVE-2026-6397 - Sticky Plugin

The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmoretext` attribute in versions up to and including 2.5.6. This is due to insufficient input sanitization and output escaping in the `cvmh_sticky_front_render()` function — the `readmoretext` attribute value is passed through `apply_filters()` and directly concatenated into the HTML output without any escaping function such as `esc_html()`. This makes it possible for authenticated attackers with Contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a page containing…

PLUGIN Sticky

CVE-2026-6397

MEDIUM CVSS 6.4 2026-05-20
Threat Entry Updated 2026-05-20

CVE-2026-5293 - Os Diagnosis Generator Plugin

The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js' parameter in versions up to and including 1.4.16. This is due to missing authorization checks and insufficient input sanitization in the themeFunc() function. The function is hooked to 'admin_init' and processes theme update requests without verifying user capabilities, allowing any authenticated user (including subscribers) to save malicious JavaScript to theme files. Additionally, the save() function uses stripslashes() which removes WordPress's magic quotes protection. This makes it possible for authenticated attackers, with subscriber-level access and…

PLUGIN Os Diagnosis Generator

CVE-2026-5293

MEDIUM CVSS 6.4 2026-05-20
Threat Entry Updated 2026-05-20

CVE-2026-6395 - Word 2 Cash Plugin

The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. This is due to the complete absence of nonce verification on the settings save handler in the w2c_admin() function, combined with missing input sanitization before storage and missing output escaping when rendering the stored value. The w2c-definitions POST parameter is saved raw via update_option() and later echoed without escaping inside a element. This makes it possible for unauthenticated attackers to forge a request on behalf…

PLUGIN Word 2 Cash

CVE-2026-6395

MEDIUM CVSS 6.1 2026-05-20
Threat Entry Updated 2026-05-20

CVE-2026-6391 - Sentence To Seo Plugin

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the create_admin_page() function. This makes it possible for unauthenticated attackers to inject malicious web scripts and update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Sentence To Seo

CVE-2026-6391

MEDIUM CVSS 6.1 2026-05-20
Threat Entry Updated 2026-05-20

CVE-2026-6394 - Nexa Blocks Plugin

The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due to the import_demo() function accepting a user-supplied URL in the demo_json_file POST parameter and passing it directly to wp_remote_get() without any URL validation or restriction against internal or private network destinations. The nexa_blocks_nonce required for the AJAX action is publicly exposed in the HTML source of any frontend page where the plugin is active via wp_localize_script on…

PLUGIN Nexa Blocks

CVE-2026-6394

MEDIUM CVSS 5.4 2026-05-20
Threat Entry Updated 2026-05-20

CVE-2026-6399 - General Options Plugin

The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.1.0. This is due to the use of sanitize_text_field() for output escaping in the Contact Number (ad_contact_number) field — a function that strips HTML tags but does not encode double-quote characters to their HTML entity equivalent ("). When the stored value is echoed inside a double-quoted HTML attribute (value="..."), an attacker-supplied double-quote character breaks out of the attribute context. Even with WordPress's wp_magic_quotes mechanism (which prefixes quotes with a backslash), the resulting…

PLUGIN General Options

CVE-2026-6399

MEDIUM CVSS 4.4 2026-05-20
Threat Entry Updated 2026-05-19

CVE-2026-8096 - Kirki – Freeform Page Builder, Website Builder & Customizer Theme

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view all Kirki frontend forms and read stored visitor form submission data, including contact details, messages, and any other visitor-provided information submitted through site forms.

THEME Kirki – Freeform Page Builder, Website Builder & Customizer

CVE-2026-8096

MEDIUM CVSS 6.5 2026-05-19
Threat Entry Updated 2026-05-19

CVE-2026-45442 - Presto Player Plugin

Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.3.

PLUGIN Presto Player

CVE-2026-45442

MEDIUM CVSS 4.3 2026-05-19
Threat Entry Updated 2026-05-18

CVE-2026-1631 - Before 2 Plugin

The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4's license key due to a missing capability check on the 'actions' function. This makes it possible for subscribers and above delete the license key.

PLUGIN Before 2

CVE-2026-1631

MEDIUM CVSS 5.4 2026-05-18
Threat Entry Updated 2026-05-18

CVE-2026-8681 - Essential Chat Support Plugin

The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to reset all plugin configuration settings — including general settings, display rules, custom CSS, and WooCommerce tab settings — to their defaults by sending a POST request with ecs_reset_settings=1.

PLUGIN Essential Chat Support

CVE-2026-8681

MEDIUM CVSS 5.3 2026-05-16
Threat Entry Updated 2026-05-15

CVE-2026-6415 - Advanced Custom Fields Font Awesome Plugin

The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON field values and unsafe client-side HTML construction in the update_preview() JavaScript function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Advanced Custom Fields Font Awesome

CVE-2026-6415

MEDIUM CVSS 6.4 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-7046 - Nex Forms Express Wp Form Builder Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Nex Forms Express Wp Form Builder

CVE-2026-7046

MEDIUM CVSS 4.9 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-8425 - Notify Odoo Plugin

The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the _updateSettings function. This makes it possible for unauthenticated attackers to change the Notify Odoo URL to an attacker-controlled URL and modify notification, tracking image, and allowed IP address settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Notify Odoo

CVE-2026-8425

MEDIUM CVSS 4.3 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-7563 - Business Directory Plugin

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to add arbitrary notes to any order and trigger unsolicited notification and moderation emails to listing owners without administrative authorization.

PLUGIN Business Directory

CVE-2026-7563

MEDIUM CVSS 4.3 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-4683 - Smartcat Translator For Wpml Plugin

The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'routeData' REST endpoint in all versions up to, and including, 3.1.77. This makes it possible for unauthenticated attackers to overwrite the plugin's Smartcat API credentials (account ID, API secret key, hub key, API host, and hub host), effectively hijacking the translation service or causing a denial of service.

PLUGIN Smartcat Translator For Wpml

CVE-2026-4683

MEDIUM CVSS 6.5 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-6646 - The7 — Website and eCommerce Builder for WordPress Theme

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is due to insufficient input sanitization and output escaping on the 'title' component of the 'link' shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME The7 — Website and eCommerce Builder for WordPress

CVE-2026-6646

MEDIUM CVSS 6.4 2026-05-15
Threat Entry Updated 2026-05-14

CVE-2026-6504 - Royal Elementor Addons And Templates Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Royal Elementor Addons And Templates

CVE-2026-6504

MEDIUM CVSS 6.4 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-6174 - Cc Child Pages Plugin

The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cc Child Pages

CVE-2026-6174

MEDIUM CVSS 6.4 2026-05-14
Scroll to top