Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 221-240 of 12246 records
Threat Entry Updated 2026-07-09

CVE-2026-13253 - Ultimate Post Plugin

The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/advanced-search block in versions up to and including 5.0.31. This is due to insufficient input sanitization and output escaping in the Advanced_Search::content() render callback: the attribute value is filtered with wp_kses(), which strips disallowed HTML tags but does NOT escape HTML special characters such as double quotes in plain text, and the result is then concatenated directly into the data-viewmoretext HTML attribute without esc_attr(). This makes it possible for authenticated attackers,…

PLUGIN Ultimate Post

CVE-2026-13253

MEDIUM CVSS 6.4 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-13334 - Mang Board Wp Plugin

The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Mang Board Wp

CVE-2026-13334

MEDIUM CVSS 6.1 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-13450 - GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.9.4 via the 'access' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view private GamiPress activity log entries belonging to any user, including badge earnings, points balance changes, and event records from integrated plugins such as WooCommerce, LearnDash, and BuddyPress. This is exploitable by any unauthenticated visitor because the…

PLUGIN GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

CVE-2026-13450

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-12418 - User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration Plugin

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite the post_title, post_content, and post_excerpt of any arbitrary post on the site, including posts authored by administrators. Exploitation requires access to any WPUF post submission form; this is achievable by users with no WordPress role, as…

PLUGIN User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

CVE-2026-12418

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-12170 - AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' attribute in all versions up to, and including, 10.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

CVE-2026-12170

MEDIUM CVSS 6.4 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-12406 - User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration Plugin

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to delete arbitrary media attachments whose post_author is 0, such as guest and registration-form uploads, via the wpuf_file_del AJAX action. This is exploitable by unauthenticated visitors on any site where a WPUF shortcode is rendered…

PLUGIN User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

CVE-2026-12406

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-11359 - Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration Plugin

The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid() AJAX handler registered via wp_ajax_pg_install_profilegrid. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the ProfileGrid plugin from wordpress.

PLUGIN Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration

CVE-2026-11359

MEDIUM CVSS 4.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-12270 - Everest Forms Plugin

The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header. This makes it possible for unauthenticated attackers to read onboarding status information, modify the related Everest Forms WordPress plugin before 3.5.0 options, and trigger an email from the site to an arbitrary address.

PLUGIN Everest Forms

CVE-2026-12270

MEDIUM CVSS 6.5 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-12517 - Fediverse Embeds Plugin

The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and private-network URLs and read back the parsed page metadata. This is a Server-Side Request Forgery.

PLUGIN Fediverse Embeds

CVE-2026-12517

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-12516 - Fediverse Embeds Plugin

The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body. This results in a full-read Server-Side Request Forgery and open proxy.

PLUGIN Fediverse Embeds

CVE-2026-12516

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-11875 - Wp Support Plus Responsive Ticket System Plugin

The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person's support tickets.

PLUGIN Wp Support Plus Responsive Ticket System

CVE-2026-11875

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-11869 - Before 3 Plugin

The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.

PLUGIN Before 3

CVE-2026-11869

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-08

CVE-2026-6740 - Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder Theme

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

CVE-2026-6740

MEDIUM CVSS 6.4 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6459 - Essential Addons for Elementor – Popular Elementor Templates & Widgets Plugin

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on event titles sourced from The Events Calendar. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons for Elementor – Popular Elementor Templates & Widgets

CVE-2026-6459

MEDIUM CVSS 6.4 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-5459 - User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration Plugin

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on the 'user_id' user controlled key. This makes it possible for unauthenticated attackers to activate a free subscription pack for any user on the site, overwriting their existing paid subscription and causing loss of paid features.

PLUGIN User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

CVE-2026-5459

MEDIUM CVSS 5.3 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12002 - Smash Balloon Social Photo Feed – Easy Social Feeds Plugin

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Smash Balloon Social Photo Feed – Easy Social Feeds Plugin

CVE-2026-12002

MEDIUM CVSS 4.7 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6742 - Advanced Iframe Plugin

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Advanced Iframe

CVE-2026-6742

MEDIUM CVSS 6.4 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14250 - TH Login Registration Theme

The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled 'role' parameter and validating it only against get_editable_roles() — which returns every defined editable site role, including 'editor' — before passing it to wp_insert_user(). This makes it possible for unauthenticated attackers, when public user registration is enabled, to create new accounts with the editor role.

THEME TH Login Registration

CVE-2026-14250

MEDIUM CVSS 6.3 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12936 - Recurio – Ultimate Subscription for WooCommerce Plugin

The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 1.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Recurio – Ultimate Subscription for WooCommerce

CVE-2026-12936

MEDIUM CVSS 4.9 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-9731 - Wp Js Detect Plugin

The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorrect nonce validation on the plugin_settings function. This makes it possible for unauthenticated attackers to update the plugin's notification text and CSS settings (wp_non_js_notification_text and wp_non_js_notification_css), injecting arbitrary content that is echoed unescaped on the frontend via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Js Detect

CVE-2026-9731

MEDIUM CVSS 4.3 2026-07-08
Scroll to top