Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 661-680 of 12246 records
Threat Entry Updated 2026-06-17

CVE-2026-8976 - Feedzy Rss Feeds Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to create and execute RSS import jobs, purge (force-delete) all posts associated with any import job, clear import error logs, and enumerate taxonomy terms and post meta_key names.…

PLUGIN Feedzy Rss Feeds

CVE-2026-8976

MEDIUM CVSS 4.3 2026-06-06
Threat Entry Updated 2026-06-17

CVE-2026-8893 - Wp Stripe Express Plugin

The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] shortcode in versions up to, and including, 1.28.0. This is due to insufficient input sanitization and output escaping on the shortcode attribute value, which is concatenated into an HTML attribute in the rendered output of the register_shortcode() function without being passed through esc_attr() or any other escaping function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will…

PLUGIN Wp Stripe Express

CVE-2026-8893

MEDIUM CVSS 6.4 2026-06-06
Threat Entry Updated 2026-06-17

CVE-2026-8608 - Event Monster Plugin

The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 2.1.0. This is due to the capture_payment() AJAX handler (registered via wp_ajax_nopriv_em_capture_payment) trusting client-supplied payment data — including transaction ID, amount, and payment status — without performing any server-side verification against the PayPal API or any other payment gateway, and without nonce or capability checks. This makes it possible for unauthenticated attackers to forge payment records, mark bookings as Completed, and obtain confirmation emails…

PLUGIN Event Monster

CVE-2026-8608

MEDIUM CVSS 5.3 2026-06-06
Threat Entry Updated 2026-06-17

CVE-2026-6448 - Quiz Master Next Plugin

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. If the secret key is…

PLUGIN Quiz Master Next

CVE-2026-6448

MEDIUM CVSS 4.9 2026-06-06
Threat Entry Updated 2026-06-17

CVE-2026-7047 - Frontend User Notes Plugin

The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the funp_ajax_modify_notes function. This makes it possible for unauthenticated attackers to trick a logged-in user into visiting a malicious page, causing unauthorized overwriting of that victim's own note content via a forged cross-site request to wp_update_post() via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Due to…

PLUGIN Frontend User Notes

CVE-2026-7047

MEDIUM CVSS 4.3 2026-06-06
Threat Entry Updated 2026-06-17

CVE-2026-10038 - Charitable Plugin

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insecure Direct Object Reference / Authorization Bypass leading to Arbitrary Attachment Deletion in versions up to, and including, 1.8.11.1 via the profile avatar update flow. This is due to the save_avatar() function in Charitable_Profile_Form calling wp_delete_attachment() on an attachment ID read from the user's 'avatar' meta without validating that the attachment is owned by the user, combined with Charitable_Data_Processor::process_picture() returning the raw posted value when no file is uploaded, allowing…

PLUGIN Charitable

CVE-2026-10038

MEDIUM CVSS 4.3 2026-06-06
Threat Entry Updated 2026-06-17

CVE-2026-7523 - Alba Board Plugin

The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access arbitrary private alba_card post data, including title, description, assignee, due date, tags, and comments, that is intended to be restricted to Administrators and Editors. The handler is registered via the wp_ajax_nopriv_ hook and its nonce is exposed to all…

PLUGIN Alba Board

CVE-2026-7523

MEDIUM CVSS 4.3 2026-06-05
Threat Entry Updated 2026-06-17

CVE-2026-49077 - WP eMember Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2.

PLUGIN WP eMember

CVE-2026-49077

MEDIUM CVSS 5.3 2026-06-04
Threat Entry Updated 2026-06-17

CVE-2026-8653 - Masterstudy Lms Pro Plus Plugin

The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with instructor-level access or above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Masterstudy Lms Pro Plus

CVE-2026-8653

MEDIUM CVSS 6.5 2026-06-04
Threat Entry Updated 2026-06-17

CVE-2026-9732 - Legacy Deliverance Plugin

The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the form_settings_ui (settings save handler, procedural include scope) function. This makes it possible for unauthenticated attackers to modify plugin settings including the minimum access role (altering WordPress role capabilities via add_cap/remove_cap), the data-erasure-on-uninstall flag, life-check timing values, the mandator email address, the confirmation page ID, and date/time formats via a forged request granted they…

PLUGIN Legacy Deliverance

CVE-2026-9732

MEDIUM CVSS 4.3 2026-06-03
Threat Entry Updated 2026-06-17

CVE-2026-7421 - Passeum Ticketing Plugin

The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name` setting value without sanitization when it begins with "http", combined with insufficient validation in the `validate_shop_name()` function which only checks for empty values and string type. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary external scripts by setting the `shop_name` to an attacker-controlled URL (e.g., `https://attacker.com`), which causes the plugin to enqueue external…

PLUGIN Passeum Ticketing

CVE-2026-7421

MEDIUM CVSS 4.4 2026-06-03
Threat Entry Updated 2026-06-17

CVE-2026-5074 - Armember Premium Plugin

The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient sanitization of the user-supplied parameter which is concatenated directly into the ORDER BY clause of an SQL query without a whitelist check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note: The vulnerability…

PLUGIN Armember Premium

CVE-2026-5074

MEDIUM CVSS 6.5 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-49782 - Elementor Plugin

Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through 4.1.0.

PLUGIN Elementor

CVE-2026-49782

MEDIUM CVSS 5.4 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-28116 - Progress Planner Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored XSS. This issue affects Progress Planner: from n/a through 1.9.0.

PLUGIN Progress Planner

CVE-2026-28116

MEDIUM CVSS 5.9 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-27351 - Crew HRM Plugin

Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crew HRM: from n/a through 1.2.2.

PLUGIN Crew HRM

CVE-2026-27351

MEDIUM CVSS 5.4 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-5191 - Tiled Gallery Carousel Without Jetpack Plugin

The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'data-image-title' parameter in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tiled Gallery Carousel Without Jetpack

CVE-2026-5191

MEDIUM CVSS 5.4 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-9730 - Remove Nofollow Commenter Link Plugin

The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify the plugin's comment-display setting via a forged request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Remove Nofollow Commenter Link

CVE-2026-9730

MEDIUM CVSS 4.3 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-9723 - Google Plus One Bottom Plugin

The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect nonce validation on the googlePlusOneAdmin function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the plusone-lang, plusone-callback, and plusone-url options stored in the database via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Google Plus One Bottom

CVE-2026-9723

MEDIUM CVSS 4.3 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-9722 - Laiser Tag Plugin

The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the addOptionsPageFields function. This makes it possible for unauthenticated attackers to update the plugin's settings, including the API key, tag blacklist, relevance threshold, batch size, and tagging toggles, via a forged request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Laiser Tag

CVE-2026-9722

MEDIUM CVSS 4.3 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-9599 - Tectite Forms Plugin

The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the tectite_forms_button option, via a forged request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Tectite Forms

CVE-2026-9599

MEDIUM CVSS 4.3 2026-06-02
Scroll to top