Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total57
Critical0
High0
Medium0
Reset
Showing 1-20 of 57 records
Threat Entry Updated 2026-08-11

CVE-2026-14549 - Ray Enterprise Translation Plugin

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site's configured languages.

PLUGIN Ray Enterprise Translation

CVE-2026-14549

UNKNOWN CVSS 0.0 2026-08-11
Threat Entry Updated 2026-08-11

CVE-2026-14548 - Ray Enterprise Translation Plugin

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value.

PLUGIN Ray Enterprise Translation

CVE-2026-14548

UNKNOWN CVSS 0.0 2026-08-11
Threat Entry Updated 2026-08-10

CVE-2026-19089 - Product Input Fields For Woocommerce Plugin

The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules.

PLUGIN Product Input Fields For Woocommerce

CVE-2026-19089

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-19077 - Duplicate Post Plugin

The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users.

PLUGIN Duplicate Post

CVE-2026-19077

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-19049 - Prosolution Wp Client Plugin

The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores.

PLUGIN Prosolution Wp Client

CVE-2026-19049

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-18960 - Block User Account Plugin

The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.

PLUGIN Block User Account

CVE-2026-18960

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-18934 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import job, reset its deduplication and scheduling state, disable it, or clear its error log. One of the affected actions performs no object-type check either, so arbitrary posts and pages can also be unpublished regardless of who owns them.

PLUGIN Rss Aggregator By Feedzy

CVE-2026-18934

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-18786 - Authentication Error Raised For Any Request Whose Uri Merely Contains A Checkview Plugin

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to a logged-in administrator, such as creating a new administrator account, via a crafted link an administrator is tricked into opening.

PLUGIN Authentication Error Raised For Any Request Whose Uri Merely Contains A Checkview

CVE-2026-18786

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-18666 - Library Management System Plugin

The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including user password hashes.

PLUGIN Library Management System

CVE-2026-18666

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-18469 - Register Forms Plugin

The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification code and the per-source attempt counter on client-controlled data, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.

PLUGIN Register Forms

CVE-2026-18469

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-18468 - Register Forms Plugin

The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.

PLUGIN Register Forms

CVE-2026-18468

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-18200 - Before 1 Plugin

The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.

PLUGIN Before 1

CVE-2026-18200

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-18030 - Exploitation Requires The Site To Have A Form Using The Bricksforge Plugin

The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and take over their account. Exploitation requires the site to have a form using the BricksForge WordPress plugin before 3.1.8.8's password reset action in its update mode. The server-side current-password verification option for that action is disabled by default, so the vulnerable state is the default one once the action is…

PLUGIN Exploitation Requires The Site To Have A Form Using The Bricksforge

CVE-2026-18030

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-17540 - File Manager Plugin

The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.

PLUGIN File Manager

CVE-2026-17540

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-17023 - Salon Booking System Plugin

The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.

PLUGIN Salon Booking System

CVE-2026-17023

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-17021 - Salon Booking System Plugin

The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.

PLUGIN Salon Booking System

CVE-2026-17021

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-17020 - Salon Booking System Plugin

The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.

PLUGIN Salon Booking System

CVE-2026-17020

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-17018 - Cubewp Framework Plugin

The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators.

PLUGIN Cubewp Framework

CVE-2026-17018

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-17016 - Stripe With Subscriptions For Woocommerce Plugin

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.

PLUGIN Stripe With Subscriptions For Woocommerce

CVE-2026-17016

UNKNOWN CVSS 0.0 2026-08-10
Scroll to top