Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 521-540 of 12246 records
Threat Entry Updated 2026-06-17

CVE-2026-40722 - Yoast SEO Plugin

Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.

PLUGIN Yoast SEO

CVE-2026-40722

MEDIUM CVSS 5.5 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-12115 - Counter Box Plugin

The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via…

PLUGIN Counter Box

CVE-2026-12115

MEDIUM CVSS 6.6 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-40809 - Metro Magazine Plugin

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.

PLUGIN Metro Magazine

CVE-2026-40809

MEDIUM CVSS 6.5 2026-06-16
Threat Entry Updated 2026-06-17

CVE-2026-2381 - Woocommerce Gateway Stripe Plugin

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment for an order via the `wc_stripe_pay_for_order` WC-AJAX endpoint. The function only validates a nonce (which is publicly available on any WooCommerce page where Express Checkout is enabled), but does not verify that the requesting user owns the target order and is allowed to…

PLUGIN Woocommerce Gateway Stripe

CVE-2026-2381

MEDIUM CVSS 6.5 2026-06-16
Threat Entry Updated 2026-06-17

CVE-2026-10093 - User Private Files Plugin

The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN User Private Files

CVE-2026-10093

MEDIUM CVSS 6.4 2026-06-16
Scroll to top