Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 681-700 of 12246 records
Threat Entry Updated 2026-06-17

CVE-2026-9234 - Woo Jtl Connector Plugin

The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability checks and nonce verification on the admin_post_settings_save_woo-jtl-connector action (handled by JtlConnectorAdmin::save()) and on the wp_ajax_downloadJTLLogs and wp_ajax_clearJTLLogs AJAX actions (handled by the global downloadJTLLogs() and clearJTLLogs() functions). This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary plugin settings, download a ZIP archive of the connector's developer log files, and delete those log files.

PLUGIN Woo Jtl Connector

CVE-2026-9234

MEDIUM CVSS 4.3 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-8885 - Demomentsomtres Shortcodes Plugin

The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on the 'width' and 'align' shortcode attributes within the st_callout() function, which concatenates the attribute values directly into an HTML style attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Demomentsomtres Shortcodes

CVE-2026-8885

MEDIUM CVSS 6.4 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-4081 - Zem Stl Viewer Plugin

The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the 'url', 'color', and 'bgcolor' parameters. These attribute values are directly interpolated into HTML attribute context without being passed through esc_attr() or any other escaping function. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user…

PLUGIN Zem Stl Viewer

CVE-2026-4081

MEDIUM CVSS 6.4 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-4080 - Easy Cart Plugin

The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the ectp_add_to_cart() function uses sanitize_text_field() on shortcode attributes like 'itemid', 'product_name', 'product_desc', 'product_qty', and 'price' before inserting them into double-quoted HTML attributes. While sanitize_text_field() strips HTML tags, it does not escape double quote characters, allowing an attacker to break out of the HTML attribute context and inject arbitrary event handlers. This…

PLUGIN Easy Cart

CVE-2026-4080

MEDIUM CVSS 6.4 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-3620 - Word Replacer Plugin

The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and including, 0.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Word Replacer

CVE-2026-3620

MEDIUM CVSS 4.4 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-8422 - Remove Meta Boxes Per User Role Plugin

The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This is due to missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' page. This makes it possible for unauthenticated attackers to modify or reset the plugin's per-role meta box visibility settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Remove Meta Boxes Per User Role

CVE-2026-8422

MEDIUM CVSS 4.3 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-4071 - Birdseed Plugin

The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing nonce validation in the birdseed_plugin_settings_page() function. The function processes the 'birdseed_token' GET parameter and saves it to the database via update_option() without verifying a nonce. This makes it possible for unauthenticated attackers to change the plugin's BirdSeed token setting via a forged request, granted they can trick a site administrator into performing an action such as clicking a link.

PLUGIN Birdseed

CVE-2026-4071

MEDIUM CVSS 4.3 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-2382 - Fpw Category Thumbnails Plugin

The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX action in all versions up to, and including, 1.9.5. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the plugin's settings page.

PLUGIN Fpw Category Thumbnails

CVE-2026-2382

MEDIUM CVSS 6.4 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-2425 - Hiweb Migration Simple Plugin

The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into performing an action such as clicking on a link.

PLUGIN Hiweb Migration Simple

CVE-2026-2425

MEDIUM CVSS 6.1 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-1451 - Rognone Plugin

The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Rognone

CVE-2026-1451

MEDIUM CVSS 6.1 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-1450 - Rognone Plugin

The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Rognone

CVE-2026-1450

MEDIUM CVSS 6.1 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-3722 - Auto Image Attributes From Filename With Bulk Updater Plugin

The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment metadata in all versions up to, and including, 4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Auto Image Attributes From Filename With Bulk Updater

CVE-2026-3722

MEDIUM CVSS 6.4 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-10100 - Simple Custom Login Page Plugin

The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, Link Color) in versions up to and including 1.0.3. This is due to insufficient input sanitization of the color option values (they were registered with register_setting() and stored via the Settings API/update_option() with no sanitize_callback) combined with the values being output into a block on wp-login.php using esc_attr(), which is incorrect for a CSS context (it does not escape ;, {, }, / or *).…

PLUGIN Simple Custom Login Page

CVE-2026-10100

MEDIUM CVSS 4.4 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-9050 - Slider Revolution Plugin

The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to deactivate any active plugin installed on the site.

PLUGIN Slider Revolution

CVE-2026-9050

MEDIUM CVSS 4.3 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-9048 - Slider Revolution Plugin

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw social media API credentials: the Instagram OAuth token, Flickr API key, YouTube Data API key, and Facebook App ID, stored in any configured slider's settings.

PLUGIN Slider Revolution

CVE-2026-9048

MEDIUM CVSS 4.3 2026-06-02
Threat Entry Updated 2026-06-17

CVE-2026-42679 - Classified Listing Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8.

PLUGIN Classified Listing

CVE-2026-42679

MEDIUM CVSS 6.5 2026-06-01
Threat Entry Updated 2026-06-17

CVE-2026-42676 - myCred Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects myCred: from n/a through 3.0.4.

PLUGIN myCred

CVE-2026-42676

MEDIUM CVSS 6.5 2026-06-01
Threat Entry Updated 2026-06-17

CVE-2026-42671 - GeoDirectory Plugin

Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.

PLUGIN GeoDirectory

CVE-2026-42671

MEDIUM CVSS 6.5 2026-06-01
Threat Entry Updated 2026-06-17

CVE-2026-8382 - Advanced Custom Fields Plugin

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and post_content of any post bound to a publicly accessible acf_form() instance by injecting values into the _post_title and _post_content parameters of a form submission request.

PLUGIN Advanced Custom Fields

CVE-2026-8382

MEDIUM CVSS 5.3 2026-05-31
Threat Entry Updated 2026-07-21

CVE-2026-9189 - Contact Form 7 Paypal Add On Plugin

The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by posting back to PayPal with `cmd=_notify-validate`, it fails to compare the IPN payload's `mc_gross` (payment amount), `mc_currency`, or `receiver_email` fields against the corresponding stored order values before passing the attacker-controlled `invoice` field directly to `cf7pp_complete_payment()`, which marks the order completed after only an integer cast with no amount verification. This makes it…

PLUGIN Contact Form 7 Paypal Add On

CVE-2026-9189

MEDIUM CVSS 5.3 2026-05-29
Scroll to top