Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 481-500 of 12246 records
Threat Entry Updated 2026-06-23

CVE-2026-7547 - Integration Marktplaats For Woocommerce Plugin

The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and including 2.0.4. This is due to insufficient path sanitization in the render_logs_ui() function, which accepts a base64-encoded file name from the 'log_file' GET parameter and concatenates it directly with the plugin's log directory path without validating that the resolved path remains within the intended directory. This makes it possible for authenticated attackers, with Administrator-level access, to read the contents of arbitrary files on the server, including wp-config.

PLUGIN Integration Marktplaats For Woocommerce

CVE-2026-7547

MEDIUM CVSS 4.9 2026-06-19
Threat Entry Updated 2026-06-22

CVE-2026-4328 - Advanced Import Plugin

The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() to fetch a user-supplied URL without validating that the URL does not point to internal or private network resources in the demo_download_and_unzip() function. The 'demo_file' parameter from $_POST is passed through sanitize_text_field() (which only handles XSS-related sanitization) and then directly into wp_remote_get() when 'demo_file_type' is set to 'url'. Notably, the plugin uses wp_safe_remote_get() in other locations (theme template libraries) which would provide…

PLUGIN Advanced Import

CVE-2026-4328

MEDIUM CVSS 6.4 2026-06-19
Threat Entry Updated 2026-06-23

CVE-2026-11989 - Bit Integrations Plugin

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.7 via the upload_attachment. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Exploitation requires a form integration to be configured with a field mapped to a WooCommerce product image, product gallery, downloadable files, or Google Contacts attachment field,…

PLUGIN Bit Integrations

CVE-2026-11989

MEDIUM CVSS 6.5 2026-06-19
Threat Entry Updated 2026-06-22

CVE-2026-12157 - Block Editor Plugin

The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs/category-slate-layout Gutenberg block in versions up to, and including, 4.5.3. This is due to insufficient input sanitization and output escaping in the CategorySlateLayout::render() method, which echoes the blockId block attribute directly into an HTML class attribute without esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever…

PLUGIN Block Editor

CVE-2026-12157

MEDIUM CVSS 6.4 2026-06-19
Threat Entry Updated 2026-06-22

CVE-2026-1856 - Creavi Booking Service Plugin

The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Creavi Booking Service

CVE-2026-1856

MEDIUM CVSS 6.4 2026-06-19
Threat Entry Updated 2026-06-22

CVE-2026-12430 - Blocksy Companion Plugin

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Blocksy Companion

CVE-2026-12430

MEDIUM CVSS 4.4 2026-06-19
Threat Entry Updated 2026-06-22

CVE-2026-10779 - Classified Listing Plugin

The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check on the gallery_image_update_as_feature AJAX handler (action: rtcl_fb_gallery_image_update_as_feature), which accepts a user-supplied listing ID and attachment ID and sets the featured image of a listing while only validating a nonce that is exposed to any logged-in user on the frontend listing-submission form. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the featured…

PLUGIN Classified Listing

CVE-2026-10779

MEDIUM CVSS 4.3 2026-06-19
Threat Entry Updated 2026-06-22

CVE-2026-10034 - Shapepress Dsgvo Plugin

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.39. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to supply an arbitrary victim email address and trigger immediate SAR processing via the process_now and is_ajax parameters, receiving tokenized download links (zip_link, pdf_link) in the HTTP response that expose the victim's personal data — including WordPress account details, comment author names, email addresses,…

PLUGIN Shapepress Dsgvo

CVE-2026-10034

MEDIUM CVSS 5.3 2026-06-19
Threat Entry Updated 2026-06-22

CVE-2026-11775 - User Admin Simplifier Plugin

The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the useradminsimplifier_options_page function. This makes it possible for unauthenticated attackers to reset and permanently delete any user's stored menu and admin-bar configuration via a forged request that triggers uas_save_admin_options() and overwrites the useradminsimplifier_options database entry via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN User Admin Simplifier

CVE-2026-11775

MEDIUM CVSS 4.3 2026-06-19
Threat Entry Updated 2026-07-01

CVE-2026-56024 - WP EasyPay Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.5.0.

PLUGIN WP EasyPay

CVE-2026-56024

MEDIUM CVSS 6.5 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-56009 - Bricksable for Bricks Builder Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored XSS. This issue affects Bricksable for Bricks Builder: from n/a through 1.6.83.

PLUGIN Bricksable for Bricks Builder

CVE-2026-56009

MEDIUM CVSS 5.9 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-56007 - Ocean Product Sharing Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Product Sharing allows Stored XSS. This issue affects Ocean Product Sharing: from n/a through 2.2.2.

PLUGIN Ocean Product Sharing

CVE-2026-56007

MEDIUM CVSS 5.9 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-8039 - Fancy Testimonials Plugin

The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Fancy Testimonials

CVE-2026-8039

MEDIUM CVSS 6.4 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-2021 - Slideshow Gallery Plugin

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versions up to, and including, 1.8.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slideshow Gallery

CVE-2026-2021

MEDIUM CVSS 6.4 2026-06-18
Threat Entry Updated 2026-06-22

CVE-2026-9815 - Magicform Plugin

The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on the server.

PLUGIN Magicform

CVE-2026-9815

MEDIUM CVSS 6.5 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-12136 - Customize My Account For Woocommerce Plugin

The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is due to insufficient input sanitization and output escaping on user supplied attributes (min_height, min_width, max_height, max_width) in the wcmamtx_get_avatar_default() function, which are concatenated unescaped into the get_avatar() extra_attr style attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Customize My Account For Woocommerce

CVE-2026-12136

MEDIUM CVSS 6.4 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-12098 - Powerpress Podcasting Plugin By Blubrry

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all versions up to, and including, 11.16.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The embed value is stored via update_post_meta() rather than through WordPress core's post content pipeline, meaning kses-on-save filtering is never applied — even for Author-role…

PLUGIN Powerpress Podcasting Plugin By Blubrry

CVE-2026-12098

MEDIUM CVSS 6.4 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-12137 - Customize My Account For Woocommerce Plugin

The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Because the vulnerable plugin_options_page() function is only rendered within the WordPress admin dashboard, successful…

PLUGIN Customize My Account For Woocommerce

CVE-2026-12137

MEDIUM CVSS 6.1 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-12111 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the cpabc_calendar_load2=1 query parameter in wp-admin and only checks is_admin() && current_user_can('edit_posts'), a capability available to Contributor-level users and above. This makes it possible for authenticated attackers with Contributor-level access and above to supply an arbitrary calendar ID via the id parameter and extract customer booking information, including email addresses, names,…

PLUGIN Appointment Booking Calendar

CVE-2026-12111

MEDIUM CVSS 4.3 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-9199 - Accessibility Checker Plugin

The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to dismiss, ignore, or restore accessibility audit issue records belonging to posts they are not permitted to edit by supplying an issue from their own post as an authorization token to…

PLUGIN Accessibility Checker

CVE-2026-9199

MEDIUM CVSS 4.3 2026-06-18
Scroll to top