Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,807
Critical0
High0
Medium10,807
Reset
Showing 541-560 of 10807 records
Threat Entry Updated 2026-04-15

CVE-2026-2502 - Xmlrpc Attacks Blocker Plugin

The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0, via the 'X-Forwarded-For' HTTP header. This is due to the plugin trusting and logging attacker-controlled IP header data and rendering debug log entries without output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the debug log page.

PLUGIN Xmlrpc Attacks Blocker

CVE-2026-2502

MEDIUM CVSS 6.1 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-2284 - News Element Plugin

The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.8. This is due to a missing capability check and nonce verification on the 'ne_clean_data' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to truncate 8 core WordPress database tables (posts, comments, terms, term_relationships, term_taxonomy, postmeta, commentmeta, termmeta) and delete the entire WordPress uploads directory, resulting in complete data loss.

PLUGIN News Element

CVE-2026-2284

MEDIUM CVSS 5.4 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-2282 - Slidorion Plugin

The Slidorion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Slidorion

CVE-2026-2282

MEDIUM CVSS 4.4 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-2504 - Dealia – Request a quote Plugin

The Dealia – Request a quote plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on multiple AJAX handlers in all versions up to, and including, 1.0.7. The admin nonce (DEALIA_ADMIN_NONCE) is exposed to all users with edit_posts capability (Contributor+) via wp_localize_script() in PostsController.php, while the AJAX handlers in AdminSettingsController.php only verify the nonce without checking current_user_can('manage_options'). This makes it possible for authenticated attackers, with Contributor-level access and above, to reset the plugin configuration.

PLUGIN Dealia – Request a quote

CVE-2026-2504

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-1646 - Advance Block Extend Plugin

The Advance Block Extend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TitleColor block attribute in the Latest Posts Gutenberg block in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Advance Block Extend

CVE-2026-1646

MEDIUM CVSS 6.4 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-1455 - Whatsiplus Scheduled Notification For Woocommerce Plugin

The Whatsiplus Scheduled Notification for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing nonce validation on the 'wsnfw_save_users_settings' AJAX action. This makes it possible for unauthenticated attackers to modify plugin configuration settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Whatsiplus Scheduled Notification For Woocommerce

CVE-2026-1455

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-1373 - Easy Author Image Plugin

The Easy Author Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author_profile_picture_url' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Author Image

CVE-2026-1373

MEDIUM CVSS 6.4 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-1055 - Talkjs Plugin

The TalkJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Talkjs

CVE-2026-1055

MEDIUM CVSS 4.4 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-1047 - salavat counter Plugin

The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' parameter in all versions up to, and including, 0.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN salavat counter Plugin

CVE-2026-1047

MEDIUM CVSS 4.4 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-1044 - Tennis Court Bookings Plugin

The Tennis Court Bookings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Tennis Court Bookings

CVE-2026-1044

MEDIUM CVSS 4.4 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-1043 - Postmarkapp Email Integrator Plugin

The PostmarkApp Email Integrator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 2.4. This is due to insufficient input sanitization and output escaping on the pma_api_key and pma_sender_address parameters. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the settings page.

PLUGIN Postmarkapp Email Integrator

CVE-2026-1043

MEDIUM CVSS 4.4 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-0722 - Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Plugin

The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed via user-supplied parameter in the 'isNonceVerifyRequired' function. This makes it possible for unauthenticated attackers to execute SQL injection attacks, extracting sensitive information from the database, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Shield: Blocks Bots, Protects Users, and Prevents Security Breaches

CVE-2026-0722

MEDIUM CVSS 6.5 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-0556 - Xo Event Calendar Plugin

The XO Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xo_event_field' shortcode in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Xo Event Calendar

CVE-2026-0556

MEDIUM CVSS 6.4 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-0549 - Groups Plugin

The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Groups

CVE-2026-0549

MEDIUM CVSS 6.4 2026-02-19
Threat Entry Updated 2026-04-15

CVE-2026-0561 - Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Plugin

The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 21.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Shield: Blocks Bots, Protects Users, and Prevents Security Breaches

CVE-2026-0561

MEDIUM CVSS 6.1 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-14983 - Advanced Custom Fields Font Awesome Plugin

The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible forauthenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts that execute in a victim's browser.

PLUGIN Advanced Custom Fields Font Awesome

CVE-2025-14983

MEDIUM CVSS 6.4 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-14851 - Yamaps For Wordpress Plugin

The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `yamap` shortcode parameters in all versions up to, and including, 0.6.40 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Yamaps For Wordpress

CVE-2025-14851

MEDIUM CVSS 6.4 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-14445 - Devvn Image Hotspot Plugin

The Image Hotspot by DevVN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hotspot_content' custom field meta in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Devvn Image Hotspot

CVE-2025-14445

MEDIUM CVSS 6.4 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-14357 - Mega Store Woocommerce Theme

The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the setup_widgets() function in core/includes/importer/whizzie.php in all versions up to, and including, 5.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary pages and modify site settings.

THEME Mega Store Woocommerce

CVE-2025-14357

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-14864 - Virusdie One Click Website Security Plugin

The Virusdie - One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.7. This is due to missing capability checks on the `vd_get_apikey` function which is hooked to `wp_ajax_virusdie_apikey`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve the site's Virusdie API key, which could be used to access the site owner's Virusdie account and potentially compromise site security.

PLUGIN Virusdie One Click Website Security

CVE-2025-14864

MEDIUM CVSS 4.3 2026-02-19
Scroll to top