Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 321-340 of 12246 records
Threat Entry Updated 2026-07-01

CVE-2026-27435 - Woffice Plugin

Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.

PLUGIN Woffice

CVE-2026-27435

MEDIUM CVSS 5.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-13454 - Motopress Appointment Booking Plugin

The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the mpa_appointment_employee custom role, meaning any user assigned this role can perform…

PLUGIN Motopress Appointment Booking

CVE-2026-13454

MEDIUM CVSS 6.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12754 - VikBooking Hotel Booking Engine & PMS Plugin

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the targeted page to render the [vikbooking view="roomslist"] shortcode, as the vulnerable layoutstyle parameter is only processed in that…

PLUGIN VikBooking Hotel Booking Engine & PMS

CVE-2026-12754

MEDIUM CVSS 6.1 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-13733 - Download Manager Plugin

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although wp_kses_post is applied to post content on save, it only strips HTML tokens and does not neutralize C-style escape sequences embedded within shortcode attribute values, meaning contributors can…

PLUGIN Download Manager

CVE-2026-13733

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12732 - LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, and including, 4.4.0. This is due to insufficient input sanitization and output escaping in the FilterCourseTemplate::sections() method at line 98, where the attacker-controlled attribute is inserted into an HTML class attribute via sprintf('', $class_wrapper_form) without esc_attr() escaping. The FilterCourseShortcode::render() handler does not apply shortcode_atts() filtering, so raw user attributes flow directly through do_action('learn-press/filter-courses/layout', $data) into the template. This makes it possible for authenticated attackers, with contributor-level access and above, to…

PLUGIN LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

CVE-2026-12732

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12435 - Motors – Car Dealership & Classified Listings Plugin

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to mark or unmark any other user's car listing as sold by replaying a valid nonce harvested from their own listing against an arbitrary victim post ID, triggering a site-wide 'Sold' badge on the victim's…

PLUGIN Motors – Car Dealership & Classified Listings Plugin

CVE-2026-12435

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12408 - Slim SEO – A Fast & Automated SEO Plugin For WordPress

The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Content Disclosure in all versions up to, and including, 4.9.8 via the `/wp-json/slim-seo/meta-tags/ai` REST API endpoint. This is due to the endpoint's `permission_callback` performing only a top-level `edit_posts` capability check without verifying that the requesting user has read access to the specific post supplied via the `object.ID` parameter, allowing the `generate` function to pass the attacker-controlled post ID to `Data::get_post_content()`, which calls `get_post()` regardless of post status or ownership. This…

PLUGIN Slim SEO – A Fast & Automated SEO Plugin For WordPress

CVE-2026-12408

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-10096 - Qi Blocks Plugin

The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to modify the stored Qi Blocks styles of arbitrary posts, templates, or widgets they do not own — including site-wide surfaces via the reserved 'template' and 'widget' page_id values — enabling unauthorized frontend defacement, content hiding, and degradation of any page on the site.…

PLUGIN Qi Blocks

CVE-2026-10096

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11887 - Salon Booking System Plugin

The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings.

PLUGIN Salon Booking System

CVE-2026-11887

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11570 - User Submitted Posts Plugin

The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an admin-configured display template, leading to a Stored Cross-Site Scripting that can be triggered by unauthenticated users when a non-default display option is enabled.

PLUGIN User Submitted Posts

CVE-2026-11570

MEDIUM CVSS 4.2 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11562 - Ws Form Lite Plugin

The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions, allowing authenticated users with subscriber-level access and above to modify the WS Form LITE WordPress plugin before 1.11.8's settings.

PLUGIN Ws Form Lite

CVE-2026-11562

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-9107 - Kali Forms — Contact Form & Drag-and-Drop Builder Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Kali Forms — Contact Form & Drag-and-Drop Builder

CVE-2026-9107

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-2387 - Event Organiser Plugin

The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.12.9. This is due to the 'eo_events' shortcode accepting attacker-controlled 'no_events' content and rendering it in event list templates without output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Event Organiser

CVE-2026-2387

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-13443 - Elearning And Online Course Solution Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in all versions up to, and including, 3.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elearning And Online Course Solution

CVE-2026-13443

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-13246 - Donation Plugin And Fundraising Platform

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_id' (and other) shortcode attributes of the 'givewp_campaign_comments' shortcode in versions up to, and including, 4.16.0. This is due to insufficient input sanitization and output escaping on user supplied attributes in CampaignCommentsShortcode::parseAttributes() and BlockRenderController::render(), where the blockId value is interpolated directly into a single-quoted HTML attribute without esc_attr(). This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever…

PLUGIN Donation Plugin And Fundraising Platform

CVE-2026-13246

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-13015 - Wp Google Places Review Slider Plugin

The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is URL-decoded, stripslashes()'d, and echoed directly into an HTML value attribute with no esc_attr() call when the supplied place is not already a stored key in the wprev_google_crawls option. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can…

PLUGIN Wp Google Places Review Slider

CVE-2026-13015

MEDIUM CVSS 6.1 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12110 - Taskbuilder – Project Management & Task Management Tool With Kanban Board Plugin

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'task_search' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The wppm_get_task_list AJAX handler performs no…

PLUGIN Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-12110

MEDIUM CVSS 6.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12135 - Fv Flowplayer Video Player Plugin

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Fv Flowplayer Video Player

CVE-2026-12135

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12127 - WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More Plugin

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name through smart-tag expansion with context `'notification'` instead of `'notification-reply-to'`, which bypasses email-address validation while `wpforms_sanitize_textarea_field()` intentionally preserves CR/LF characters that are never stripped before the display name is concatenated into the raw `Reply-To:` mail header string. This makes it possible for unauthenticated attackers…

PLUGIN WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

CVE-2026-12127

MEDIUM CVSS 5.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12904 - Kadence Blocks Plugin

The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.7.7. This is due to a mismatch between the object used for authorization and the object actually accessed in the Optimize_Rest_Controller's create_item(), get_item(), delete_item(), and bulk_delete_items() endpoints — authorization is checked via current_user_can('edit_post'/'delete_post', $post_id) against the user-supplied post_id, while the storage layer keys analysis records on sha256($post_path) from a separately supplied, attacker-controlled post_path parameter, with no enforcement that post_path corresponds to post_id. This makes…

PLUGIN Kadence Blocks

CVE-2026-12904

MEDIUM CVSS 4.3 2026-07-01
Scroll to top