Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12,246
Critical0
High0
Medium12,246
Reset
Showing 161-180 of 12246 records
Threat Entry Updated 2026-07-13

CVE-2026-13262 - Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val' parameter in all versions up to, and including, 1.1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a valid 'get-smart-reply' nonce, which any Subscriber-level user can…

PLUGIN Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin

CVE-2026-13262

MEDIUM CVSS 6.5 2026-07-11
Threat Entry Updated 2026-07-14

CVE-2026-12426 - Members – Membership & User Role Editor Plugin

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest. This makes it possible for unauthenticated attackers to extract determine the existence and exact count of access-restricted posts, and use per-page pagination as a boolean oracle to infer keywords and content contained within those hidden restricted posts.

PLUGIN Members – Membership & User Role Editor Plugin

CVE-2026-12426

MEDIUM CVSS 5.3 2026-07-11
Threat Entry Updated 2026-07-15

CVE-2026-10628 - Points And Rewards For Woocommerce Plugin

The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.10.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to convert and drain any user's reward points into wallet balance, exfiltrate all users' emails and point balances to an attacker-controlled Klaviyo account, overwrite the site's Klaviyo public API key, block or unblock arbitrary users from the points…

PLUGIN Points And Rewards For Woocommerce

CVE-2026-10628

MEDIUM CVSS 4.3 2026-07-11
Threat Entry Updated 2026-07-13

CVE-2026-11426 - Under Construction Page (Pro) Plugin

The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to the plugin accepting arbitrary local file paths in the template_thumbnail parameter and copying their contents into a publicly accessible uploads file. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary files on the server, which can contain sensitive information.

PLUGIN Under Construction Page (Pro)

CVE-2026-11426

MEDIUM CVSS 6.5 2026-07-11
Threat Entry Updated 2026-07-13

CVE-2026-13039 - Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) Plugin

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the plugin not properly verifying that a user is authorized to perform an action in the payment_complete() function of PaymentController.php. This makes it possible for unauthenticated attackers to mark unpaid ticket orders as completed by submitting a fabricated SureCart checkout ID or FluentCart cart hash, granting themselves paid event access, QR-code attendee tickets,…

PLUGIN Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

CVE-2026-13039

MEDIUM CVSS 5.3 2026-07-10
Threat Entry Updated 2026-07-14

CVE-2026-15295 - Ajax Load More – Infinite Scroll, Load More, & Lazy Load Plugin

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Ajax Load More – Infinite Scroll, Load More, & Lazy Load

CVE-2026-15295

MEDIUM CVSS 4.4 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-9857 - Saskaita123 Lt Plugin

The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the plugin's API key stored in wp_options, modify invoice plugin settings, and alter WooCommerce tax rate data in the wp_woocommerce_tax_rates table.

PLUGIN Saskaita123 Lt

CVE-2026-9857

MEDIUM CVSS 4.3 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-13010 - Joomsport Sports League Results Management Plugin

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortcode Attribute in all versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The shortcode can be embedded in…

PLUGIN Joomsport Sports League Results Management

CVE-2026-13010

MEDIUM CVSS 6.5 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-13710 - Jeg Elementor Kit Plugin

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget's 'sg_body_description' parameter in versions up to, and including, 3.2.6. This is due to insufficient input sanitization and output escaping on the description attribute in the render_body() method of the Image_Box_View class — every other attribute used by the method is wrapped in esc_attr(), but the description value is concatenated directly into HTML body context. This makes it possible for authenticated attackers,…

PLUGIN Jeg Elementor Kit

CVE-2026-13710

MEDIUM CVSS 6.4 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-13247 - Logo Slider Wp Plugin

The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lgx_tooltip_position' parameter in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Logo Slider Wp

CVE-2026-13247

MEDIUM CVSS 6.4 2026-07-10
Threat Entry Updated 2026-07-14

CVE-2026-12918 - Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails Plugin

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to generic SQL Injection via the 'recipients' parameter in all versions up to, and including, 1.24.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection:…

PLUGIN Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails

CVE-2026-12918

MEDIUM CVSS 4.9 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-11990 - Kivicare Clinic Management System Plugin

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending appointments as Confirmed and forge an associated completed payment record in wp_kc_payments_appointment_mappings using an attacker-supplied payment ID, bypassing payment entirely. This exploit is achievable on a default installation because the gateway resolution logic returns all registered…

PLUGIN Kivicare Clinic Management System

CVE-2026-11990

MEDIUM CVSS 5.3 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-9838 - Ics Calendar Plugin

The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and including, 12.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is reachable via the unauthenticated wp_ajax_nopriv_r34ics_ajax AJAX action, which accepts attacker-controlled js_args values merged over stored shortcode configuration without nonce verification, allowing the…

PLUGIN Ics Calendar

CVE-2026-9838

MEDIUM CVSS 6.1 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15104 - Faq With Chatbot Plugin

The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter in all versions up to, and including, 4.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a supported multilingual plugin…

PLUGIN Faq With Chatbot

CVE-2026-15104

MEDIUM CVSS 6.5 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-3907 - Hostel Plugin

The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all versions up to and including 1.1.7. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the second shortcode attribute (used as button text) is passed to the `$text` variable without sanitization at line 79 and then output directly into an HTML `value` attribute at line 91 without `esc_attr()` or any other escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary…

PLUGIN Hostel

CVE-2026-3907

MEDIUM CVSS 6.4 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-6802 - Easy Upload Files During Checkout Plugin

The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is due to missing authorization checks in the ufdc_custom_init() function, which processes the 'eufdc-delete' parameter without any nonce verification, capability check, or attachment ownership validation. This makes it possible for unauthenticated attackers to permanently delete arbitrary media library attachments from the WordPress site.

PLUGIN Easy Upload Files During Checkout

CVE-2026-6802

MEDIUM CVSS 5.3 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-14475 - Gdpr Cookie Consent Plugin

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 'scan_id' parameter in all versions up to, and including, 4.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Gdpr Cookie Consent

CVE-2026-14475

MEDIUM CVSS 4.9 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15026 - Import And Export Users And Customers Plugin

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw post_content of arbitrary posts regardless of status (draft, private, future, trash, password-protected) or post type (including non-public CPTs such as WooCommerce orders and internal CRM records) by enumerating post IDs. The required codection-security nonce is exposed as inline JavaScript on any wp-admin page when ?post_type=acui_email_template…

PLUGIN Import And Export Users And Customers

CVE-2026-15026

MEDIUM CVSS 4.3 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-6440 - Video Conference Plugin

The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the reset_credential() function, which handles the wp_ajax_goodmeet_reset_google_meet_credential AJAX action. While the function does verify the user's capability (manage_options), it does not validate a nonce, making it susceptible to CSRF attacks. This makes it possible for unauthenticated attackers to trick a site administrator into clicking a malicious link that will reset (delete) the plugin's…

PLUGIN Video Conference

CVE-2026-6440

MEDIUM CVSS 4.3 2026-07-10
Threat Entry Updated 2026-07-14

CVE-2026-1946 - Gw Ai Website Builder Plugin

The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disconnect the plugin from GravityWrite via the 'gwaiwebu_gravitywrite_disconnect' AJAX action.

PLUGIN Gw Ai Website Builder

CVE-2026-1946

MEDIUM CVSS 4.3 2026-07-10
Scroll to top