Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 621-640 of 12246 records
Threat Entry Updated 2026-06-17

CVE-2026-8907 - Wp Ultimate Map Plugin

The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing nonce validation on the process_init() function hooked to admin_init, which saves plugin settings (zoom-level, focus-lat, focus-lng, sel_places, sel_routes) via update_option() based solely on the presence of a save-setting POST parameter. Additionally, the saved values — particularly zoom-level — are stored without sanitization and later echoed into an HTML attribute (and inline JavaScript) on the settings page without escaping. This makes it possible for unauthenticated attackers to change…

PLUGIN Wp Ultimate Map

CVE-2026-8907

MEDIUM CVSS 6.1 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8940 - Wp Meta Sort Posts Plugin

The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due to missing or incorrect nonce validation on the top-level included script in msp-options.php. This makes it possible for unauthenticated attackers to change the plugin's msp_loop_file and msp_nav_location settings via a forged request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Meta Sort Posts

CVE-2026-8940

MEDIUM CVSS 4.3 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8909 - Wp Mobi Plugin

The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3. This is due to missing or incorrect nonce validation on the handleSaveGeneralSettings function. This makes it possible for unauthenticated attackers to modify the plugin's General Settings and inject arbitrary web scripts into the administrator's browser via the unescaped app_name attribute reflection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The injected script executes even when the supplied app_name…

PLUGIN Wp Mobi

CVE-2026-8909

MEDIUM CVSS 4.3 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8904 - For Woocommerce On Steroids Plugin

The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the settingsPage function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including toggling the webhook integration and changing the FastPicker and KDZ API URLs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN For Woocommerce On Steroids

CVE-2026-8904

MEDIUM CVSS 4.3 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8902 - Report Comments Plugin

The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect nonce validation on the rc_options_page function. This makes it possible for unauthenticated attackers to modify plugin settings including link text and markup, success/failure/already-reported messages, comment threshold, cookie duration, reporter-comment toggle, and notification email address, subject, and message body via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Report Comments

CVE-2026-8902

MEDIUM CVSS 4.3 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8883 - Global Body Mass Index Calculator Plugin

The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmicalc' shortcode in versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes in the GBMI_Calc_Widget::widget() function. Shortcode attributes are extracted directly into local variables via @extract($args) and then echoed unescaped into an HTML style attribute (height/width) and HTML body context (title), allowing attribute-breakout payloads. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in…

PLUGIN Global Body Mass Index Calculator

CVE-2026-8883

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8882 - Wp Applicantstack Jobs Display Plugin

The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Applicantstack Jobs Display

CVE-2026-8882

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8880 - Romancart Ecommerce Plugin

The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (and other attributes) of the romancart_button shortcode in versions up to, and including, 2.0.8. This is due to insufficient input sanitization and output escaping on user supplied attributes within the romancart_button_shortcode() function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Romancart Ecommerce

CVE-2026-8880

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8841 - Extra Settings For Rocketchat Plugin

The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat' shortcode's 'title' attribute in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping in the rxstg_shortcode() function, which concatenates the user-supplied 'title' attribute directly into HTML output. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Extra Settings For Rocketchat

CVE-2026-8841

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-7662 - Epaperflip Publisher Plugin

The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attribute of the `epaperflip_embed` shortcode in all versions up to, and including, 1. This is due to insufficient input sanitization and output escaping on the shortcode attribute which is injected directly into inline JavaScript. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Epaperflip Publisher

CVE-2026-7662

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8499 - Helpfulcrowd Product Reviews Plugin

The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1.2.9. This is due to the `helpfulcrowd_validate_token()` function using a loose comparison operator (`!=`) instead of a strict comparison (`!==`) when validating the `token` parameter, while the corresponding REST route `/wp-json/helpfulcrowd/v1/update-settings` is registered with a `permission_callback` of `__return_true`, making it reachable by unauthenticated users; submitting a JSON boolean `true` as the `token` value causes PHP's loose comparison to evaluate as equal to the non-empty base64-encoded secret string, bypassing…

PLUGIN Helpfulcrowd Product Reviews

CVE-2026-8499

MEDIUM CVSS 5.3 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-11603 - Product Filter Widget For Elementor Plugin

The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The endpoint is registered via wp_ajax_nopriv_ with no nonce verification or capability check, and exploitation is delivered via a CSRF-style form auto-submission to…

PLUGIN Product Filter Widget For Elementor

CVE-2026-11603

MEDIUM CVSS 6.1 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-10738 - Jquery Hover Footnotes Plugin

The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{...}}' Syntax) in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attribute-breakout payload (e.g., a double-quote followed by an event handler) contains no angle brackets and therefore bypasses WordPress core's wp_kses_post() filtering, which only strips disallowed HTML…

PLUGIN Jquery Hover Footnotes

CVE-2026-10738

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-10024 - 360crest Themeone Tinymce Shortcodes Plugin

The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Attribute in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN 360crest Themeone Tinymce Shortcodes

CVE-2026-10024

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-10553 - Jquery Hover Footnotes Plugin

The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the jqFootnotes_options_subpanel function. This makes it possible for unauthenticated attackers to update the plugin's settings with arbitrary values that, because option values such as jqfoot_anchor_open, jqfoot_anchor_close, and jqfoot_title are echoed unescaped into frontend page content, can be chained into persistent Cross-Site Scripting affecting all site visitors via a forged request granted they can trick a site administrator into performing…

PLUGIN Jquery Hover Footnotes

CVE-2026-10553

MEDIUM CVSS 4.3 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-5714 - Enable Media Replace Plugin

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parameter in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Enable Media Replace

CVE-2026-5714

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-10862 - Accordions Plugin

The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2.3.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Accordions

CVE-2026-10862

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-3011 - Recipe Card Blocks By Wpzoom Plugin

The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into HTML characters after sanitization has already been applied. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses the published post or the print view of an injected recipe.

PLUGIN Recipe Card Blocks By Wpzoom

CVE-2026-3011

MEDIUM CVSS 6.4 2026-06-08
Threat Entry Updated 2026-06-17

CVE-2026-9829 - Photo Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'compact_album_order_by' Shortcode Parameter in all versions up to, and including, 1.8.41 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The malicious payload is stored via the 'shortcode_bwg' AJAX…

PLUGIN Photo Gallery

CVE-2026-9829

MEDIUM CVSS 6.5 2026-06-06
Threat Entry Updated 2026-06-17

CVE-2026-9016 - Debug Log Manager Plugin

The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Neutralization for Logs in all versions up to, and including, 2.5.0. This is due to the `log_js_errors()` AJAX handler being registered for unauthenticated users via `wp_ajax_nopriv_log_js_errors` and gated only by a nonce that is publicly disclosed in every front-end page's HTML through `wp_localize_script()` whenever JavaScript error logging is enabled, providing no real authorization barrier. This makes it possible for unauthenticated attackers to inject arbitrary forged entries into the site's WordPress debug log…

PLUGIN Debug Log Manager

CVE-2026-9016

MEDIUM CVSS 5.3 2026-06-06
Scroll to top