Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,225
Critical1,270
High4,356
Medium12,382
Reset
Showing 2161-2180 of 18225 records
Threat Entry Updated 2026-06-17

CVE-2026-1250 - Court Reservation Plugin

The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.10.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Court Reservation

CVE-2026-1250

HIGH CVSS 7.5 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-25431 - Hustle Plugin

Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hustle: through 7.8.10.1.

PLUGIN Hustle

CVE-2026-25431

MEDIUM CVSS 5.3 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-45218 - WP Travel Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows Blind SQL Injection.This issue affects WP Travel: from n/a through

PLUGIN WP Travel

CVE-2026-45218

HIGH CVSS 7.7 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-45214 - Elementor Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Blind SQL Injection.This issue affects Xpro Elementor Addons: from n/a through

PLUGIN Elementor

CVE-2026-45214

HIGH CVSS 8.5 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-45211 - APIExperts Square for WooCommerce Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through

PLUGIN APIExperts Square for WooCommerce

CVE-2026-45211

HIGH CVSS 8.5 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-42742 - WPForms Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite allows Blind SQL Injection.This issue affects Views for WPForms: from n/a through

PLUGIN WPForms

CVE-2026-42742

HIGH CVSS 8.5 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-42741 - Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend views-for-ninja-forms allows Blind SQL Injection.This issue affects Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend: from n/a through

PLUGIN Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend

CVE-2026-42741

HIGH CVSS 8.5 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-45213 - BEAR Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQL Injection.This issue affects BEAR: from n/a through

PLUGIN BEAR

CVE-2026-45213

HIGH CVSS 7.6 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-45210 - Broadstreet Ads Plugin

Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broadstreet Ads: from n/a through

PLUGIN Broadstreet Ads

CVE-2026-45210

MEDIUM CVSS 5.4 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-45215 - WP EasyPay Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Embedded Sensitive Data.This issue affects WP EasyPay: from n/a through

PLUGIN WP EasyPay

CVE-2026-45215

MEDIUM CVSS 5.3 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-45212 - Asset CleanUp: Page Speed Booster Plugin

Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through

PLUGIN Asset CleanUp: Page Speed Booster

CVE-2026-45212

MEDIUM CVSS 5.3 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-6813 - Continually Plugin

The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Continually

CVE-2026-6813

MEDIUM CVSS 4.4 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-6800 - Fastbots Ai Chatbots Plugin

The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Fastbots Ai Chatbots

CVE-2026-6800

MEDIUM CVSS 4.4 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-1934 - Motors Car Dealership Classified Listings Plugin

The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the stm_save_user_extra_fields() function updating sensitive user meta fields from POST data without verifying that the current user should have permission to modify those fields. The function hooks into the 'personal_options_update' action and only checks current_user_can('edit_user', $user_id), which passes for any user editing their own profile. This makes it possible for authenticated attackers, with Subscriber-level access and above,…

PLUGIN Motors Car Dealership Classified Listings

CVE-2026-1934

MEDIUM CVSS 4.3 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-7661 - Bootstrap Shortcode Plugin

The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `box` shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bootstrap Shortcode

CVE-2026-7661

MEDIUM CVSS 6.4 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-7659 - Advanced Social Media Icons Plugin

The Advanced Social Media Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `social` shortcode in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Advanced Social Media Icons

CVE-2026-7659

MEDIUM CVSS 6.4 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-7561 - Tm Wordpress Redirection Plugin

The Tm – WordPress Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Tm Wordpress Redirection

CVE-2026-7561

MEDIUM CVSS 6.1 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-7464 - Wp Google Maps Integration Plugin

The WP Google Maps Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into performing an action such as clicking on a link.

PLUGIN Wp Google Maps Integration

CVE-2026-7464

MEDIUM CVSS 6.1 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-7437 - Azonpost Plugin

The AzonPost plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `editpos_hidden` parameter in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into performing an action such as clicking on a link.

PLUGIN Azonpost

CVE-2026-7437

MEDIUM CVSS 6.1 2026-05-12
Threat Entry Updated 2026-06-17

CVE-2026-7626 - Slek Gateway For Woocommerce Plugin

The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due to the wsb_handle_slek_payment_redirect() function placing the merchant's slek_key and slek_secret API credentials directly into a client-side HTML form, and additionally embedding the slek_secret as a plaintext GET parameter in the IPN callback URL. This makes it possible for unauthenticated attackers who can place an order on the affected store to extract the merchant's API credentials by viewing the HTML source or using browser DevTools on the WooCommerce order-pay page before the…

PLUGIN Slek Gateway For Woocommerce

CVE-2026-7626

MEDIUM CVSS 5.3 2026-05-12
Scroll to top