Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 601-620 of 12246 records
Threat Entry Updated 2026-06-17

CVE-2026-46698 - fediverse-embeds-wordpress-plugin

Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.php) that verified a nonce ftf-fediverse-embeds-nonce and then called file_get_html($site_url) on the attacker-supplied URL. The same nonce was enqueued onto every public page containing a fediverse embed (via includes/Enqueue_Assets.php lines 41-46 + includes/Helpers.php lines 64-83), so the nonce gate was not an authentication boundary; any visitor of a public post with an embed could grab it and reuse it. This issue has been patched in version 1.5.9.

PLUGIN fediverse-embeds-wordpress-plugin

CVE-2026-46698

MEDIUM CVSS 5.3 2026-06-11
Threat Entry Updated 2026-06-17

CVE-2026-2827 - Open User Map Pro Plugin

The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notification' parameter in versions up to, and including, 1.4.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Open User Map Pro

CVE-2026-2827

MEDIUM CVSS 4.7 2026-06-11
Threat Entry Updated 2026-06-17

CVE-2026-53742 - Simple Link Directory Plugin

Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.

PLUGIN Simple Link Directory

CVE-2026-53742

MEDIUM CVSS 5.1 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-53741 - Simple Link Directory Plugin

Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor.

PLUGIN Simple Link Directory

CVE-2026-53741

MEDIUM CVSS 5.1 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-53740 - Duplicate Post Plugin

Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice.

PLUGIN Duplicate Post

CVE-2026-53740

MEDIUM CVSS 5.1 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-53739 - Duplicate Post Plugin

Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authenticated user into sending a request that sets the duplicate_post_show_notice site option, suppressing admin notices network-wide.

PLUGIN Duplicate Post

CVE-2026-53739

MEDIUM CVSS 5.1 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-53737 - Juicer Plugin

Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.

PLUGIN Juicer

CVE-2026-53737

MEDIUM CVSS 5.3 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-53736 - Easy Twitter Feeds Plugin

Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into visiting a crafted link that duplicates any post regardless of post type.

PLUGIN Easy Twitter Feeds

CVE-2026-53736

MEDIUM CVSS 5.1 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-9019 - Easy Image Collage Plugin

The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters in all versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the data is stored via update_post_meta() rather than wp_insert_post() post content, WordPress's unfiltered_html restriction does not apply, meaning Authors cannot be blocked from this attack path…

PLUGIN Easy Image Collage

CVE-2026-9019

MEDIUM CVSS 6.4 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-8613 - Athemes Addons For Elementor Lite Plugin

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This affects the Posts Timeline widget as well as the Posts Carousel widget across its default, Banner, and Modern skins, all of which omit the whitelist validation…

PLUGIN Athemes Addons For Elementor Lite

CVE-2026-8613

MEDIUM CVSS 6.4 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-8853 - Mw Wp Form Plugin

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the memo value is stored via update_post_meta() rather than wp_insert_post(), WordPress's built-in kses and unfiltered_html protections do not apply, allowing attackers to break out of the textarea…

PLUGIN Mw Wp Form

CVE-2026-8853

MEDIUM CVSS 4.4 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-53675 - Buddypress Plugin

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections.

PLUGIN Buddypress

CVE-2026-53675

MEDIUM CVSS 5.3 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-4058 - User Registration Plugin

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel any user's subscription pack, including administrators.

PLUGIN User Registration

CVE-2026-4058

MEDIUM CVSS 4.3 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8677 - Unlimited Elementor Inner Sections By Boomdevs Plugin

The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit succeeds even for users without the unfiltered_html capability because the payload (e.g., 'img src=x onerror=alert(document.domain)') contains no HTML…

PLUGIN Unlimited Elementor Inner Sections By Boomdevs

CVE-2026-8677

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8599 - Woocommerce Emails Plugin

The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Campaign HTML Content Field in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The public-facing campaign preview endpoint (/mp-email/{id}-slug/) is not affected by this vulnerability, as it applies a Content-Security-Policy header blocking all…

PLUGIN Woocommerce Emails

CVE-2026-8599

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-18

CVE-2026-7542 - Slider Revolution Plugin

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to and including 7.0.10. This is due to three compounding design flaws: (1) the plugin leaks a valid backend AJAX nonce (revslider_actions) to all authenticated users including Subscribers via the admin_footer hook; (2) the wordpress.create.image_from_url action is explicitly allowlisted in the $user_allowed array, bypassing the administrator-only access control; (3) the create_wordpress_image_from_url() function accepts an attacker-controlled url parameter that is passed to import_media(), where path_or_url_exists() explicitly accepts local filesystem paths (file_exists() && is_readable()) with no restriction…

PLUGIN Slider Revolution

CVE-2026-7542

MEDIUM CVSS 6.5 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-4986 - Before 1 Plugin

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

PLUGIN Before 1

CVE-2026-4986

MEDIUM CVSS 5.3 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8977 - Wp Gdpr Cookie Consent Plugin

The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the gdprConfig values and missing output escaping in the generateCSS() function which echoes stored configuration values directly into a block rendered on wp_head. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute…

PLUGIN Wp Gdpr Cookie Consent

CVE-2026-8977

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8895 - Kk Blog Card Plugin

The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcode in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping on the shortcode's 'href' and 'type' attributes, which are concatenated directly into HTML attribute contexts in the shortcode callback registered in kk-blog-card-shortcode.php. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Kk Blog Card

CVE-2026-8895

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8910 - Wp Emoticon Rating Plugin

The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Emoticon Rating

CVE-2026-8910

MEDIUM CVSS 6.1 2026-06-09
Scroll to top