Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-12404 - Nex Forms Express Wp Form Builder Plugin
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enumerate sequential report IDs and download complete form submission data — including names, email addresses, phone numbers, postal addresses, payment details, and uploaded file paths — for any saved report on the site.
CVE-2026-12404
CVE-2026-13335 - Codepeople Post Map Plugin
The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-13335
CVE-2026-13422 - Hd Quiz Plugin
The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and questions, create new quizzes, and change plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2026-13422
CVE-2026-13333 - And Marketing Automation Plugin
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Sales Representative-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The sanitized Contact_Query code path can be bypassed by supplying…
CVE-2026-13333
CVE-2026-13331 - And Marketing Automation Plugin
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with marketer-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-13331
CVE-2026-11356 - Add Search To Menu Plugin
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-11356
CVE-2026-57661 - WordPress component
Subscriber Broken Access Control in WPComplete
CVE-2026-57661
CVE-2026-57665 - WordPress component
Unauthenticated Insecure Direct Object References (IDOR) in GravityView
CVE-2026-57665
CVE-2026-57660 - WordPress component
Unauthenticated Broken Access Control in Booking and Rental Manager
CVE-2026-57660
CVE-2026-57664 - WordPress component
Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder
CVE-2026-57664
CVE-2026-57654 - WordPress component
Affiliate Broken Access Control in Affiliates Manager
CVE-2026-57654
CVE-2026-57651 - WordPress component
Contributor Cross Site Scripting (XSS) in Ghost Kit
CVE-2026-57651
CVE-2026-57656 - WordPress component
Author Cross Site Scripting (XSS) in Hester Core
CVE-2026-57656
CVE-2026-57652 - WordPress component
Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk
CVE-2026-57652
CVE-2026-57657 - WordPress component
Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP
CVE-2026-57657
CVE-2026-57650 - WordPress component
Contributor Cross Site Scripting (XSS) in Magazine Blocks
CVE-2026-57650
CVE-2026-57646 - WordPress component
Subscriber Insecure Direct Object References (IDOR) in Majestic Support
CVE-2026-57646
CVE-2026-57649 - WordPress component
Subscriber Broken Access Control in Shoppable Images Lite
CVE-2026-57649
CVE-2026-57648 - WordPress component
Contributor Broken Access Control in Nelio Content
CVE-2026-57648
CVE-2026-57641 - WordPress component
Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7
CVE-2026-57641
