Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 241-260 of 12246 records
Threat Entry Updated 2026-07-08

CVE-2026-14500 - Bulk Order Update For Woocommerce Plugin

The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due to the bouw_fetch_csv_data() AJAX handler being registered on the wp_ajax_nopriv_ hook with no capability or nonce check, and passing the attacker-supplied csv_url POST parameter — filtered only by esc_url_raw() (which leaves absolute filesystem paths intact) and validate_file() (which only rejects '..' traversal patterns) — directly into fopen()/fgetcsv() and reflecting the first parsed line in the JSON response. This makes it possible for unauthenticated attackers to…

PLUGIN Bulk Order Update For Woocommerce

CVE-2026-14500

MEDIUM CVSS 5.3 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12097 - User Management Plugin

The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the plugin's export field configuration stored in the uiewp_export_field option, controlling which user fields such as password hashes are included in CSV exports and how columns are mapped during imports.

PLUGIN User Management

CVE-2026-12097

MEDIUM CVSS 5.3 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-11798 - Social Share, Social Login and Social Comments Plugin – Super Socializer

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and including, 7.14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Social Share, Social Login and Social Comments Plugin – Super Socializer

CVE-2026-11798

MEDIUM CVSS 6.1 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12041 - Chatra Live Chat + ChatBot + Cart Saver Plugin

The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Chatra Live Chat + ChatBot + Cart Saver

CVE-2026-12041

MEDIUM CVSS 4.4 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-10570 - Sympl Repeater For Acf And Elementor Plugin

The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping in the symp_arfe_replace_content() function, which uses str_replace() to substitute raw ACF field values (retrieved via get_field()) directly into Elementor-rendered HTML without any escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected…

PLUGIN Sympl Repeater For Acf And Elementor

CVE-2026-10570

MEDIUM CVSS 6.4 2026-07-08
Threat Entry Updated 2026-07-09

CVE-2026-10834 - Wp Travel Engine Plugin

The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads directory into their own profile-image path. This removes the targeted media from its original location and can break content across the site.

PLUGIN Wp Travel Engine

CVE-2026-10834

MEDIUM CVSS 4.6 2026-07-07
Threat Entry Updated 2026-07-07

CVE-2026-11328 - Exclusive Addons For Elementor Plugin

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Exclusive Addons For Elementor

CVE-2026-11328

MEDIUM CVSS 6.4 2026-07-07
Threat Entry Updated 2026-07-07

CVE-2026-12154 - Fb Reviews Widget Plugin

The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev() method, which passes the raw shortcode attribute through Feed_Old::get_feed() into the View::render() method, where it is echoed directly into the data-id HTML attribute without esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages…

PLUGIN Fb Reviews Widget

CVE-2026-12154

MEDIUM CVSS 6.4 2026-07-06
Threat Entry Updated 2026-07-07

CVE-2026-59519 - FormLayer Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.

PLUGIN FormLayer

CVE-2026-59519

MEDIUM CVSS 5.3 2026-07-05
Threat Entry Updated 2026-07-06

CVE-2026-59511 - Elementor Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.

PLUGIN Elementor

CVE-2026-59511

MEDIUM CVSS 5.3 2026-07-05
Threat Entry Updated 2026-07-06

CVE-2026-59520 - CrawlWP SEO Plugin

Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16.

PLUGIN CrawlWP SEO

CVE-2026-59520

MEDIUM CVSS 4.3 2026-07-05
Threat Entry Updated 2026-07-06

CVE-2026-5137 - Rometheme For Elementor Plugin

The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path validation on the 'template' parameter in the render_templates AJAX endpoint, which is used directly in a require/include statement without sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute files on the server ending in _templates.php, allowing the execution of any PHP code in those files.

PLUGIN Rometheme For Elementor

CVE-2026-5137

MEDIUM CVSS 4.3 2026-07-03
Threat Entry Updated 2026-07-06

CVE-2026-9756 - Generateblocks Plugin

The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A contributor-level attacker can store a JavaScript payload in their own profile description (allowlisted by get_safe_user_meta_keys()) and prepend 'javascript:' via the linkMetaFieldType attribute, creating a fully attacker-controlled…

PLUGIN Generateblocks

CVE-2026-9756

MEDIUM CVSS 6.4 2026-07-03
Threat Entry Updated 2026-07-06

CVE-2026-4804 - Zakra Theme

The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0. This is due to the theme registering three post meta fields (zakra_menu_item_color, zakra_menu_item_hover_color, and zakra_menu_item_active_color) with 'show_in_rest' => true and 'auth_callback' => '__return_true', but without any sanitize_callback parameter in the register_post_meta() calls. While the classic editor save path applies sanitize_hex_color() sanitization, the REST API path completely bypasses this protection. The unsanitized meta values are then retrieved via get_post_meta() and concatenated directly into CSS strings that are output…

THEME Zakra

CVE-2026-4804

MEDIUM CVSS 6.4 2026-07-03
Threat Entry Updated 2026-07-06

CVE-2026-11778 - Woo Multi Currency Plugin

The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.2.14. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Woo Multi Currency

CVE-2026-11778

MEDIUM CVSS 5.4 2026-07-03
Threat Entry Updated 2026-07-06

CVE-2026-11398 - Calendar Booking Plugin For Appointments And Events

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the personally identifiable information (first name, last name, phone number, and notes) of any existing customer record, including those linked to administrator accounts, by submitting the booking form with a known customer's email address. Exploitation requires the…

PLUGIN Calendar Booking Plugin For Appointments And Events

CVE-2026-11398

MEDIUM CVSS 5.3 2026-07-03
Threat Entry Updated 2026-07-07

CVE-2026-11900 - Ad Inserter Plugin

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 2.8.16 via the 'data' attribute of the [adinserter] shortcode. This is due to the replace_ai_tags() function processing a {reusable-block-N} tag pattern that calls get_post_field('post_content', N) without verifying the requesting user's capability with current_user_can('read_post'), without restricting the post type to 'wp_block', and without checking the post status. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the full content of arbitrary…

PLUGIN Ad Inserter

CVE-2026-11900

MEDIUM CVSS 4.3 2026-07-03
Threat Entry Updated 2026-07-06

CVE-2026-8351 - Rometheme For Elementor Plugin

The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in versions up to, and including, 2.0.7 This is due to insufficient output escaping on the 'background_text_heading' setting in the render() function, which concatenates the value directly into an HTML attribute without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rometheme For Elementor

CVE-2026-8351

MEDIUM CVSS 6.4 2026-07-03
Threat Entry Updated 2026-07-06

CVE-2026-9230 - Quiz Master Next Plugin

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify quizzes they do not own, overwrite quiz results pages, and reroute quiz-result notification emails to attacker-controlled addresses. An attacker first calls the /quiz/structure endpoint with an arbitrary victim quiz ID…

PLUGIN Quiz Master Next

CVE-2026-9230

MEDIUM CVSS 4.3 2026-07-03
Threat Entry Updated 2026-07-06

CVE-2026-9626 - Json Api User Plugin

The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and including, 4.1.0 This is due to insufficient input sanitization in the post_comment() function, which passes the attacker-controlled comment_content value directly to wp_insert_comment() without applying any HTML sanitization, and additionally allows the caller to set comment_approved=1 to self-approve the comment and bypass moderation. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will…

PLUGIN Json Api User

CVE-2026-9626

MEDIUM CVSS 6.4 2026-07-03
Scroll to top