Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 581-600 of 12246 records
Threat Entry Updated 2026-06-17

CVE-2026-9278 - Form Builder Cp Plugin

The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page rendering the affected form, even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).

PLUGIN Form Builder Cp

CVE-2026-9278

MEDIUM CVSS 5.4 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-8386 - Wp Go Maps Plugin

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.

PLUGIN Wp Go Maps

CVE-2026-8386

MEDIUM CVSS 5.3 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-8385 - Wp Go Maps Plugin

The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing unauthenticated visitors to retrieve marker records that the site owner has not approved for public display, including their title, category, address and description fields.

PLUGIN Wp Go Maps

CVE-2026-8385

MEDIUM CVSS 5.3 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-1291 - Meow Gallery Plugin

The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint /wp-json/meow-gallery/v1/save_shortcode in all versions up to, and including, 5.4.4 This makes it possible for authenticated attackers, with Author-level access and above, to arbitrarily create or overwrite existing gallery shortcode records by supplying a user-controlled id value. The endpoint performs database update operations without verifying that the requesting user is authorized to modify the referenced gallery record or create their own.

PLUGIN Meow Gallery

CVE-2026-1291

MEDIUM CVSS 4.3 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9629 - Canvas Plugin

The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Canvas

CVE-2026-9629

MEDIUM CVSS 6.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-3297 - Drag And Drop Website Builder Plugin

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Drag And Drop Website Builder

CVE-2026-3297

MEDIUM CVSS 6.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-2470 - Drag And Drop Website Builder Plugin

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due to the pagelayer_save_content AJAX handler allowing users with basic post-edit capability to persist pagelayer_contact_templates metadata on posts they can edit (including pending posts), while the unauthenticated pagelayer_contact_submit endpoint later consumes that metadata by user-controlled post/form identifiers without enforcing a privileged or published-context boundary. This makes it possible for authenticated attackers, with Contributor-level access and above, to configure arbitrary contact-form mail templates…

PLUGIN Drag And Drop Website Builder

CVE-2026-2470

MEDIUM CVSS 4.3 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9134 - Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel Plugin

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of HTML event attributes (onmouseover, onmouseout, onpointerenter, onclick, onload, onchange, onerror) while permitting others such as 'onmouseenter', combined with the failure to escape the attribute key when building the gallery container HTML in foogallery_build_container_attributes_safe(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject…

PLUGIN Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

CVE-2026-9134

MEDIUM CVSS 6.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-12089 - Lws Optimize Plugin

The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combine_current_css() function trusting values harvested from page HTML and converting same-site URLs to absolute filesystem paths before reading them with file_get_contents()/Minify\CSS::add(), without enforcing that the resolved path stay within ABSPATH or have a .css extension. This makes it possible for authenticated attackers, with Editor-level access and above, to read arbitrary files.

PLUGIN Lws Optimize

CVE-2026-12089

MEDIUM CVSS 4.9 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-24618 - Hash Elements Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data. This issue affects Hash Elements: from n/a through 1.5.4.

PLUGIN Hash Elements

CVE-2026-24618

MEDIUM CVSS 4.3 2026-06-12
Threat Entry Updated 2026-06-17

CVE-2026-9125 - Presto Player Plugin

The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url shortcode attribute directly into the overlay configuration without scheme validation, allowing javascript: URIs to survive and be rendered as the href of a clickable anchor element by the presto-dynamic-overlay-ui web component. This makes it possible for authenticated attackers, with contributor-level access and above, to inject…

PLUGIN Presto Player

CVE-2026-9125

MEDIUM CVSS 6.4 2026-06-12
Scroll to top