Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-49072 - WordPress component
Unauthenticated Broken Access Control in WooCommerce Anti-Fraud
CVE-2026-49072
CVE-2026-49071 - WordPress component
Unauthenticated Broken Authentication in WooCommerce Dropshipping
CVE-2026-49071
CVE-2026-45436 - WordPress component
Subscriber Broken Access Control in WPBakery Page Builder
CVE-2026-45436
CVE-2026-40724 - WordPress component
CP Client Arbitrary File Download in Client Portal (Pro)
CVE-2026-40724
CVE-2026-40722 - Yoast SEO Plugin
Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.
CVE-2026-40722
CVE-2026-40723 - WordPress component
Subscriber Broken Access Control in Bricks Builder
CVE-2026-40723
CVE-2026-39578 - WordPress component
Unauthenticated PHP Object Injection in Valiance
CVE-2026-39578
CVE-2026-39595 - WordPress component
Author Broken Access Control in W3 Total Cache
CVE-2026-39595
CVE-2026-39577 - WordPress component
Unauthenticated PHP Object Injection in Playroom
CVE-2026-39577
CVE-2026-39433 - WordPress component
Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.
CVE-2026-39433
CVE-2026-27410 - WordPress component
Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.
CVE-2026-27410
CVE-2026-24610 - WordPress component
Subscriber Broken Access Control in MetForm Pro
CVE-2026-24610
CVE-2026-24575 - WordPress component
Subscriber Broken Access Control in WishList Member X
CVE-2026-24575
CVE-2026-12115 - Counter Box Plugin
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via…
CVE-2026-12115
CVE-2026-54197 - WordPress component
Unauthenticated Sensitive Data Exposure in GetGenie
CVE-2026-54197
CVE-2026-54190 - WordPress component
Unauthenticated Broken Access Control in Envira Photo Gallery
CVE-2026-54190
CVE-2026-52714 - WordPress component
Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO
CVE-2026-52714
CVE-2026-40809 - Metro Magazine Plugin
Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.
CVE-2026-40809
CVE-2026-2381 - Woocommerce Gateway Stripe Plugin
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment for an order via the `wc_stripe_pay_for_order` WC-AJAX endpoint. The function only validates a nonce (which is publicly available on any WooCommerce page where Express Checkout is enabled), but does not verify that the requesting user owns the target order and is allowed to…
CVE-2026-2381
CVE-2026-10093 - User Private Files Plugin
The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-10093
