Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,903
Critical1,345
High4,572
Medium12,707
Reset
Showing 1-20 of 18903 records
Threat Entry Updated 2026-08-09

CVE-2026-18603 - Refund Request For Woocommerce Plugin

The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allowing unauthenticated users to disclose the contents of other customers' orders, as well as to clear and repopulate a logged in user's cart via a crafted link.

PLUGIN Refund Request For Woocommerce

CVE-2026-18603

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-18473 - Wp Directory Kit Plugin

The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

PLUGIN Wp Directory Kit

CVE-2026-18473

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-18465 - Wp Maps Pro Plugin

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary existing local PHP files on the server.

PLUGIN Wp Maps Pro

CVE-2026-18465

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-18464 - Wp Maps Pro Plugin

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.

PLUGIN Wp Maps Pro

CVE-2026-18464

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-18357 - Wpc Order Tip For Woocommerce Plugin

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and order dates.

PLUGIN Wpc Order Tip For Woocommerce

CVE-2026-18357

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-18037 - Before 2 Plugin

The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.

PLUGIN Before 2

CVE-2026-18037

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-18032 - Wp Data Access Plugin

The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, allowing unauthenticated attackers to read arbitrary columns of the database table the affected front-end form is bound to, including user password hashes where that table is the users table.

PLUGIN Wp Data Access

CVE-2026-18032

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-17044 - Iptanus File Upload Plugin

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.

PLUGIN Iptanus File Upload

CVE-2026-17044

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-17017 - Cubewp Framework Plugin

The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks.

PLUGIN Cubewp Framework

CVE-2026-17017

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-17014 - Wp Photo Album Plus Plugin

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.

PLUGIN Wp Photo Album Plus

CVE-2026-17014

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-17011 - Nexter Blocks Plugin

The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.

PLUGIN Nexter Blocks

CVE-2026-17011

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-16992 - Before 2 Plugin

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.

PLUGIN Before 2

CVE-2026-16992

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-16988 - Before 2 Plugin

The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.

PLUGIN Before 2

CVE-2026-16988

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-16965 - Solace Extra Plugin

The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.

PLUGIN Solace Extra

CVE-2026-16965

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-16957 - Slim Seo Plugin

The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own, including password-protected posts and posts of non-public post types.

PLUGIN Slim Seo

CVE-2026-16957

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-16032 - Lws Optimize Plugin

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the affected dashboard page.

PLUGIN Lws Optimize

CVE-2026-16032

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-15038 - Infinitewp Client Plugin

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.

PLUGIN Infinitewp Client

CVE-2026-15038

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-08

CVE-2026-16955 - Ai Engine Plugin

The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.

PLUGIN Ai Engine

CVE-2026-16955

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16953 - Ai Engine Plugin

The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's uploaded files.

PLUGIN Ai Engine

CVE-2026-16953

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16948 - Solace Extra Plugin

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.

PLUGIN Solace Extra

CVE-2026-16948

UNKNOWN CVSS 0.0 2026-08-08
Scroll to top