Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total57
Critical0
High0
Medium0
Reset
Showing 41-57 of 57 records
Threat Entry Updated 2026-08-09

CVE-2026-17044 - Iptanus File Upload Plugin

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.

PLUGIN Iptanus File Upload

CVE-2026-17044

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-17014 - Wp Photo Album Plus Plugin

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.

PLUGIN Wp Photo Album Plus

CVE-2026-17014

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-17011 - Nexter Blocks Plugin

The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.

PLUGIN Nexter Blocks

CVE-2026-17011

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-16992 - Before 2 Plugin

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.

PLUGIN Before 2

CVE-2026-16992

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-16965 - Solace Extra Plugin

The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.

PLUGIN Solace Extra

CVE-2026-16965

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-16957 - Slim Seo Plugin

The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own, including password-protected posts and posts of non-public post types.

PLUGIN Slim Seo

CVE-2026-16957

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-08

CVE-2026-16955 - Ai Engine Plugin

The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.

PLUGIN Ai Engine

CVE-2026-16955

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16953 - Ai Engine Plugin

The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's uploaded files.

PLUGIN Ai Engine

CVE-2026-16953

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16948 - Solace Extra Plugin

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.

PLUGIN Solace Extra

CVE-2026-16948

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16608 - Download Monitor Plugin

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.

PLUGIN Download Monitor

CVE-2026-16608

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16589 - Wp Directory Kit Plugin

The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.

PLUGIN Wp Directory Kit

CVE-2026-16589

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16574 - Ai Powered Woocommerce Multivendor Marketplace Solution Plugin

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.

PLUGIN Ai Powered Woocommerce Multivendor Marketplace Solution

CVE-2026-16574

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16559 - Ymc Filter Plugin

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.

PLUGIN Ymc Filter

CVE-2026-16559

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16282 - Appointment Hour Booking Plugin

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting booking and payment records.

PLUGIN Appointment Hour Booking

CVE-2026-16282

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16269 - Before 4 Plugin

The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when the optional API has been enabled.

PLUGIN Before 4

CVE-2026-16269

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16267 - Before 4 Plugin

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.

PLUGIN Before 4

CVE-2026-16267

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-01-26

CVE-2026-23634 - Pepr Plugin

Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not explicitly force or enforce least-privilege guidance for module authors. The default behavior exists to make the “getting started” experience smooth: new users can experiment with Pepr and create resources dynamically without needing to pre-configure RBAC. This vulnerability is fixed in 1.0.5.

PLUGIN Pepr

CVE-2026-23634

UNKNOWN CVSS 0.0 2026-01-16
Scroll to top