Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 61-80 of 12246 records
Threat Entry Updated 2026-07-17

CVE-2026-15336 - Catch Themes Demo Import Plugin

The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activate_plugin GET parameter is present, calling Plugin_Upgrader::install() to download and install a plugin from WordPress.org before performing the current_user_can('activate_plugins') capability check. This makes it possible for authenticated attackers, with subscriber-level access and above, to install the hardcoded 'essential-content-types' plugin from the WordPress.

PLUGIN Catch Themes Demo Import

CVE-2026-15336

MEDIUM CVSS 4.3 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-14987 - Donation Plugin And Fundraising Platform

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with give worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected script executes specifically when a donor clicks the Share on Twitter button on the Sequoia donation confirmation view, as that…

PLUGIN Donation Plugin And Fundraising Platform

CVE-2026-14987

MEDIUM CVSS 6.4 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12941 - Dc Woocommerce Multi Vendor Plugin

The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 5.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This vulnerability is exploitable by any authenticated subscriber-level user…

PLUGIN Dc Woocommerce Multi Vendor

CVE-2026-12941

MEDIUM CVSS 6.5 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-13005 - Mxchat Basic Plugin

The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Mxchat Basic

CVE-2026-13005

MEDIUM CVSS 4.4 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12434 - List Category Posts Plugin

The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles, full content, excerpts, dates, authors, and custom-field metadata of other users' pending-review, scheduled, and trashed posts by embedding a crafted [catlist] shortcode in their own draft and previewing it. This vulnerability is a bypass of the incomplete fix introduced for CVE-2025-11377 in version 0.93.0.

PLUGIN List Category Posts

CVE-2026-12434

MEDIUM CVSS 4.3 2026-07-16
Threat Entry Updated 2026-07-17

CVE-2026-12409 - Page Builder Add Plugin

The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. This makes it possible for unauthenticated attackers to create, update, retitle, or change the post status, slug, and type of arbitrary posts and write ULPB_DATA post meta via a forged request granted they can trick a site administrator into performing an action such as clicking…

PLUGIN Page Builder Add

CVE-2026-12409

MEDIUM CVSS 4.3 2026-07-16
Threat Entry Updated 2026-07-15

CVE-2026-11580 - Drag And Drop Builder Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own and read its private post metadata, including secrets stored by other Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17.

PLUGIN Drag And Drop Builder

CVE-2026-11580

MEDIUM CVSS 5.5 2026-07-15
Threat Entry Updated 2026-07-15

CVE-2026-11579 - Drag And Drop Builder Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress Media Library; the uploads are limited to WordPress's default-allowed MIME types, so this does not lead to code execution.

PLUGIN Drag And Drop Builder

CVE-2026-11579

MEDIUM CVSS 5.3 2026-07-15
Threat Entry Updated 2026-07-14

CVE-2026-9341 - Wordpress Lms Plugin For Complete Elearning Solution

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.0 via the 'save_lesson_note', 'get_lesson_note', and 'complete_lesson_video' AJAX handlers due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read, overwrite, or delete the private lesson notes of any other user (including administrators), and to falsify lesson-completion progress for arbitrary users.

PLUGIN Wordpress Lms Plugin For Complete Elearning Solution

CVE-2026-9341

MEDIUM CVSS 4.3 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-12988 - Wp 2fa Plugin

The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled email address and take over the account.

PLUGIN Wp 2fa

CVE-2026-12988

MEDIUM CVSS 6.4 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-11567 - Before 2 Plugin

The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden) payment amount, allowing unauthenticated users to underpay for the configured product or subscription. Forms using a fixed configured price are not affected.

PLUGIN Before 2

CVE-2026-11567

MEDIUM CVSS 5.9 2026-07-14
Threat Entry Updated 2026-07-15

CVE-2026-7640 - Customer Area Plugin

The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-content` shortcode in all versions up to, and including, 8.3.5. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Customer Area

CVE-2026-7640

MEDIUM CVSS 6.4 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-11390 - News Kit Elementor Addons Plugin

The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an attacker to intercept and modify the elementor_ajax AJAX save request in order to bypass the client-side SELECT control…

PLUGIN News Kit Elementor Addons

CVE-2026-11390

MEDIUM CVSS 6.4 2026-07-14
Threat Entry Updated 2026-07-15

CVE-2026-11802 - Foodbook Light Online Food Ordering System Plugin

The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.6. The registration() function, accessible via the wp_ajax_nopriv_registration_action AJAX action, lacks any nonce verification or capability check, and does not check the WordPress users_can_register option before calling wp_insert_user(). This makes it possible for unauthenticated attackers to create new user accounts with the 'customer' role and receive authentication cookies, even when the site administrator has explicitly disabled user registration.

PLUGIN Foodbook Light Online Food Ordering System

CVE-2026-11802

MEDIUM CVSS 5.3 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-12536 - Builder Plugin

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Module Title’ parameter in all versions up to, and including, 3.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Builder

CVE-2026-12536

MEDIUM CVSS 6.4 2026-07-13
Threat Entry Updated 2026-07-14

CVE-2026-12385 - Smart Slider 3 Plugin

The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles and full content excerpts of private, draft, pending, trashed, and auto-draft posts authored by any user, including Administrators and Editors. The required nonce is emitted on /wp-admin/post-new.php, which is accessible to Contributor-level users via the edit_posts capability, meaning any Contributor can obtain the nonce needed to trigger the injection.

PLUGIN Smart Slider 3

CVE-2026-12385

MEDIUM CVSS 4.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61985 - Car Rental Manager Plugin

Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through

PLUGIN Car Rental Manager

CVE-2026-61985

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61983 - Church Admin Plugin

Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through

PLUGIN Church Admin

CVE-2026-61983

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61977 - JetSearch Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through

PLUGIN JetSearch

CVE-2026-61977

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61976 - Elementor Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through

PLUGIN Elementor

CVE-2026-61976

MEDIUM CVSS 5.3 2026-07-13
Scroll to top