Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total57
Critical0
High0
Medium0
Reset
Showing 21-40 of 57 records
Threat Entry Updated 2026-08-10

CVE-2026-17012 - Stripe With Subscriptions For Woocommerce Plugin

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.

PLUGIN Stripe With Subscriptions For Woocommerce

CVE-2026-17012

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-16985 - Before 1 Plugin

The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution.

PLUGIN Before 1

CVE-2026-16985

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-16949 - Term Pages Plugin

The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

PLUGIN Term Pages

CVE-2026-16949

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-16299 - Single Sign On For Tng Plugin

The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

PLUGIN Single Sign On For Tng

CVE-2026-16299

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-16298 - Before 1 Plugin

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

PLUGIN Before 1

CVE-2026-16298

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-16257 - Arvow Ai Seo Writer Plugin

The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.

PLUGIN Arvow Ai Seo Writer

CVE-2026-16257

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-15238 - Motopress Hotel Booking Plugin

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.

PLUGIN Motopress Hotel Booking

CVE-2026-15238

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-15237 - Motopress Hotel Booking Plugin

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.

PLUGIN Motopress Hotel Booking

CVE-2026-15237

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-15229 - Pinpoint Booking System Plugin

The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.

PLUGIN Pinpoint Booking System

CVE-2026-15229

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-15047 - Before 260805 Does Not Escape Several Shortcode Attributes Plugin

The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).

PLUGIN Before 260805 Does Not Escape Several Shortcode Attributes

CVE-2026-15047

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-14941 - Customer Reviews For Woocommerce Plugin

The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.

PLUGIN Customer Reviews For Woocommerce

CVE-2026-14941

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-14860 - Podcast Player Plugin

The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.

PLUGIN Podcast Player

CVE-2026-14860

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-14293 - Before 5 Plugin

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.

PLUGIN Before 5

CVE-2026-14293

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-14238 - Before 3 Plugin

The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL injection.

PLUGIN Before 3

CVE-2026-14238

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-14237 - Before 3 Plugin

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.

PLUGIN Before 3

CVE-2026-14237

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-14211 - Booking For Appointments And Events Calendar Plugin

The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.

PLUGIN Booking For Appointments And Events Calendar

CVE-2026-14211

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-13600 - Autonettv Relay Plugin

The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials.

PLUGIN Autonettv Relay

CVE-2026-13600

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-13170 - Before 4 Plugin

The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.

PLUGIN Before 4

CVE-2026-13170

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-12971 - Before 4 Plugin

The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.

PLUGIN Before 4

CVE-2026-12971

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-09

CVE-2026-18037 - Before 2 Plugin

The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.

PLUGIN Before 2

CVE-2026-18037

UNKNOWN CVSS 0.0 2026-08-09
Scroll to top