Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 421-440 of 12246 records
Threat Entry Updated 2026-06-26

CVE-2026-57620 - Elementor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8.

PLUGIN Elementor

CVE-2026-57620

MEDIUM CVSS 6.5 2026-06-26
Threat Entry Updated 2026-06-26

CVE-2026-1869 - Login Builder Plugin

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.

PLUGIN Login Builder

CVE-2026-1869

MEDIUM CVSS 6.5 2026-06-26
Threat Entry Updated 2026-06-26

CVE-2026-8380 - Frontend File Manager Plugin

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin through 23.6's "Allow guest uploads" setting is enabled by an administrator, the same deletion primitive becomes reachable by unauthenticated users.

PLUGIN Frontend File Manager Plugin

CVE-2026-8380

MEDIUM CVSS 6.5 2026-06-26
Threat Entry Updated 2026-06-26

CVE-2026-13226 - And Marketing Automation Plugin

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up to, and including, 4.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Sales Manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The AJAX handler wp_ajax_groundhogg_get_contacts_table has its capability check commented…

PLUGIN And Marketing Automation

CVE-2026-13226

MEDIUM CVSS 6.5 2026-06-26
Threat Entry Updated 2026-06-25

CVE-2026-56050 - PPOM for WooCommerce Plugin

Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18.

PLUGIN PPOM for WooCommerce

CVE-2026-56050

MEDIUM CVSS 6.5 2026-06-25
Threat Entry Updated 2026-06-25

CVE-2026-10824 - Masteriyo Lms Plugin

The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.

PLUGIN Masteriyo Lms

CVE-2026-10824

MEDIUM CVSS 6.5 2026-06-25
Threat Entry Updated 2026-06-25

CVE-2026-2508 - Gravity Bookings Plugin

The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Gravity Bookings

CVE-2026-2508

MEDIUM CVSS 6.5 2026-06-25
Threat Entry Updated 2026-06-26

CVE-2026-12079 - Dokan Pro Plugin

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Dokan Pro

CVE-2026-12079

MEDIUM CVSS 6.5 2026-06-25
Threat Entry Updated 2026-06-25

CVE-2026-10833 - Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Plugin

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

CVE-2026-10833

MEDIUM CVSS 6.4 2026-06-25
Threat Entry Updated 2026-07-14

CVE-2026-53038 - Linux Plugin

In the Linux kernel, the following vulnerability has been resolved: ima_fs: Correctly create securityfs files for unsupported hash algos ima_tpm_chip->allocated_banks[i].crypto_id is initialized to HASH_ALGO__LAST if the TPM algorithm is not supported. However there are places relying on the algorithm to be valid because it is accessed by hash_algo_name[]. On 6.12.40 I observe the following read out-of-bounds in hash_algo_name: ================================================================== BUG: KASAN: global-out-of-bounds in create_securityfs_measurement_lists+0x396/0x440 Read of size 8 at addr ffffffff83e18138 by task swapper/0/1 CPU: 4 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.40 #3 Call Trace: dump_stack_lvl+0x61/0x90 print_report+0xc4/0x580…

PLUGIN Linux

CVE-2026-53038

MEDIUM CVSS 5.5 2026-06-24
Scroll to top