Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total11,547
Critical0
High0
Medium11,547
Reset
Showing 361-380 of 11547 records
Threat Entry Updated 2026-04-22

CVE-2026-6396 - Fast & Fancy Filter – 3F Plugin

The Fast & Fancy Filter – 3F plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce verification in the saveFields() function, which handles the fff_save_settins AJAX action. This makes it possible for unauthenticated attackers to modify plugin filter settings, update arbitrary options, or create new filter posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Fast & Fancy Filter – 3F

CVE-2026-6396

MEDIUM CVSS 4.3 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-6294 - Google Pagerank Display Plugin

The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validation in the gpdisplay_option() function, which handles the plugin settings page. The settings form does not include a wp_nonce_field(), and the form handler does not call check_admin_referer() or wp_verify_nonce() before processing the POST request. This makes it possible for unauthenticated attackers to trick a logged-in administrator into submitting a crafted request that changes the plugin's settings (stored via update_option()), such as the display style…

PLUGIN Google Pagerank Display

CVE-2026-6294

MEDIUM CVSS 4.3 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4280 - Breaking News Wp Plugin

The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3. This is due to the brnwp_ajax_form AJAX endpoint lacking both authorization checks and CSRF verification, combined with insufficient path validation when the brnwp_theme option value is passed directly to an include() statement in the brnwp_show_breaking_news_wp() shortcode handler. While sanitize_text_field() is applied to user input, it does not strip directory traversal sequences (../). This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the brnwp_theme option…

PLUGIN Breaking News Wp

CVE-2026-4280

MEDIUM CVSS 6.5 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-5820 - Zypento Blocks Plugin

The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and including, 1.0.6. This is due to the front-end TOC rendering script reading heading text via `innerText` and inserting it into the page using `innerHTML` without proper sanitization. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Zypento Blocks

CVE-2026-5820

MEDIUM CVSS 6.4 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-5767 - Slideshowpro Sc Plugin

The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slideshowpro Sc

CVE-2026-5767

MEDIUM CVSS 6.4 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-5748 - Text Snippet Plugin

The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in all versions up to, and including, 0.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Text Snippet

CVE-2026-5748

MEDIUM CVSS 6.4 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4353 - Ci Hub Connector Plugin

The CI HUB Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `cihub_metadata` shortcode in all versions up to, and including, 1.2.106 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ci Hub Connector

CVE-2026-4353

MEDIUM CVSS 6.4 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4279 - Bread Butter Plugin

The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-button' shortcode in all versions up to, and including, 8.2.0.25. This is due to insufficient input sanitization and output escaping on the 'event' shortcode attribute. The customEventShortCodeButton() function takes the 'event' attribute value and directly interpolates it into a JavaScript string within an onclick HTML attribute without applying esc_attr() or esc_js(). Notably, the sister function customEventShortCode() properly uses esc_js() for the same attribute, but this was omitted in the button variant. This makes it possible…

PLUGIN Bread Butter

CVE-2026-4279

MEDIUM CVSS 6.4 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4142 - Sentence To Seo Plugin

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Permanent keywords' field in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping. The plugin reads user input via filter_input_array(INPUT_POST) which applies no HTML sanitization (FILTER_DEFAULT), stores it unsanitized to the WordPress options table via update_option(), and then outputs the stored value directly into a textarea element without any escaping using PHP short echo tags (). An attacker can break out of the…

PLUGIN Sentence To Seo

CVE-2026-4142

MEDIUM CVSS 4.4 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4131 - Wp Popup Optin Plugin

The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings form on the admin page (wpo_admin_page.php) lacking nonce generation (wp_nonce_field) and verification (wp_verify_nonce/check_admin_referer). This makes it possible for unauthenticated attackers to update all plugin settings including the 'wpo_image_url' parameter via a forged request, granted they can trick a site administrator into performing an action such as clicking a link.

PLUGIN Wp Popup Optin

CVE-2026-4131

MEDIUM CVSS 6.1 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4140 - Ni Woocommerce Order Export Plugin

The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.1.6. This is due to missing nonce validation in the ni_order_export_action() AJAX handler function. The handler processes settings updates when the 'page' parameter is set to 'nioe-order-settings', delegating to Ni_Order_Setting::page_ajax() which calls update_option('ni_order_export_option', $_REQUEST) without verifying any nonce or checking user capabilities. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request, granted they can trick a site administrator into performing an action…

PLUGIN Ni Woocommerce Order Export

CVE-2026-4140

MEDIUM CVSS 4.3 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4139 - Mcatfilter Plugin

The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settings updates. The compute_post() function is called in the plugin constructor on every page load via the plugins_loaded hook, and it directly processes $_POST data to modify plugin settings via update_option() without any CSRF token validation. This makes it possible for unauthenticated attackers to modify all plugin settings, including category exclusion rules,…

PLUGIN Mcatfilter

CVE-2026-4139

MEDIUM CVSS 4.3 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4138 - Dx Unanswered Comments Plugin

The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation on the plugin's settings form in the dxuc-unanswered-comments-admin-page.php file. This makes it possible for unauthenticated attackers to modify plugin settings (dxuc_authors_list and dxuc_comment_count) via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Dx Unanswered Comments

CVE-2026-4138

MEDIUM CVSS 4.3 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4133 - Textp2p Texting Widget Plugin

The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.7. This is due to missing nonce validation in the imTextP2POptionPage() function which processes settings updates. The form at line 314 does not include a wp_nonce_field(), and the POST handler at line 7 does not call check_admin_referer() or wp_verify_nonce() before processing settings changes. This makes it possible for unauthenticated attackers to update all plugin settings including chat widget titles, messages, API credentials, colors, and reCAPTCHA configuration via a forged request,…

PLUGIN Textp2p Texting Widget

CVE-2026-4133

MEDIUM CVSS 4.3 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4125 - Wpmk Block Plugin

The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to and including 1.0.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, in the wpmk_block_shortcode() function, the 'class' attribute is extracted from user-controllable shortcode attributes and directly concatenated into an HTML div element's class attribute without any escaping (e.g., esc_attr()). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute…

PLUGIN Wpmk Block

CVE-2026-4125

MEDIUM CVSS 6.4 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4117 - Calj Plugin

The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is due to a missing capability check in the CalJSettingsPage class constructor, which processes the 'save-obtained-key' operation directly from POST data without verifying that the requesting user has the 'manage_options' capability, and without any nonce verification. The plugin bootstrap file (calj.php) instantiates CalJSettingsPage whenever is_admin() returns true, which is the case for any authenticated user making requests to wp-admin URLs (including admin-ajax.php). This makes it possible for authenticated attackers, with Subscriber-level…

PLUGIN Calj

CVE-2026-4117

MEDIUM CVSS 5.3 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4128 - Tp Restore Categories And Taxonomies Plugin

The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. The delete_term() function, which handles the 'tpmcattt_delete_term' AJAX action, does not perform any capability check (e.g., current_user_can()) to verify the user has sufficient permissions. While it does verify a nonce via check_ajax_referer(), this nonce is generated for all authenticated users via the admin_enqueue_scripts hook and exposed on any wp-admin page (including profile.php, which subscribers can access). This makes it possible for authenticated attackers, with Subscriber-level access and above,…

PLUGIN Tp Restore Categories And Taxonomies

CVE-2026-4128

MEDIUM CVSS 4.3 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4126 - Table Manager Plugin

The Table Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0 via the 'table_manager' shortcode. The shortcode handler `tablemanager_render_table_shortcode()` takes a user-controlled `table` attribute, applies only `sanitize_key()` for sanitization, and concatenates the value with `$wpdb->prefix` to form a full database table name. It then executes `DESC` and `SELECT *` queries against this table and renders all rows and columns to the frontend. There is no allowlist check to ensure only plugin-created tables can be accessed — the `tablemanager_created_tables` option is only…

PLUGIN Table Manager

CVE-2026-4126

MEDIUM CVSS 4.3 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4121 - Kcaptcha Plugin

The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1. This is due to missing nonce validation in the plugin's settings page handler (admin/setting.php). The settings form does not include a wp_nonce_field() and the form processing code does not call wp_verify_nonce() or check_admin_referer() before saving settings to the database via $wpdb->update(). This makes it possible for unauthenticated attackers to modify the plugin's CAPTCHA settings (enabling or disabling CAPTCHA on login, registration, lost password, and comment forms) via a forged request, granted…

PLUGIN Kcaptcha

CVE-2026-4121

MEDIUM CVSS 4.3 2026-04-22
Threat Entry Updated 2026-04-22

CVE-2026-4118 - Call To Action Plugin

The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.3. This is due to missing nonce validation in the cbox_options_page() function which handles saving, creating, and deleting plugin settings. The form rendered on the settings page does not include a wp_nonce_field(), and the save handler does not call wp_verify_nonce() or check_admin_referer() before processing settings updates via $wpdb->update(). This makes it possible for unauthenticated attackers to modify plugin settings such as call-to-action box title, content, link URL, image URL,…

PLUGIN Call To Action

CVE-2026-4118

MEDIUM CVSS 4.3 2026-04-22
Scroll to top