Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,225
Critical1,270
High4,356
Medium12,382
Reset
Showing 2341-2360 of 18225 records
Threat Entry Updated 2026-06-17

CVE-2026-22336 - Directorist Booking Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This issue affects Directorist Booking: from n/a before 3.0.2.

PLUGIN Directorist Booking

CVE-2026-22336

CRITICAL CVSS 9.3 2026-04-27
Threat Entry Updated 2026-06-17

CVE-2026-42379 - Templately Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data.This issue affects Templately: from n/a through 3.6.1.

PLUGIN Templately

CVE-2026-42379

HIGH CVSS 7.7 2026-04-27
Threat Entry Updated 2026-06-17

CVE-2026-7106 - Highland Software Custom Role Manager Plugin

The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked to the personal_options_update action accessible by any authenticated user. This makes it possible for authenticated attackers, with Subscriber-level access or higher, to potentially modify user roles via the profile update form.

PLUGIN Highland Software Custom Role Manager

CVE-2026-7106

HIGH CVSS 8.8 2026-04-27
Threat Entry Updated 2026-06-17

CVE-2026-4078 - Iteras Plugin

The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, iteras-signup, iteras-paywall-login, iteras-selfservice) in all versions up to and including 1.8.2. This is due to insufficient input sanitization and output escaping in the combine_attributes() function. The function directly concatenates shortcode attribute values into JavaScript code within tags using double-quoted string interpolation (line 489: '"'.$key.'": "'.$value.'"') without any escaping. An attacker can break out of the JavaScript string context by including a double-quote character in a shortcode attribute value and inject arbitrary JavaScript. This makes it…

PLUGIN Iteras

CVE-2026-4078

MEDIUM CVSS 6.4 2026-04-24
Threat Entry Updated 2026-06-17

CVE-2026-3569 - Liaison Site Prober Plugin

The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-prober/v1/logs REST API endpoint. The permissions_read() permission callback unconditionally returns true (via __return_true()) instead of checking for appropriate capabilities. This makes it possible for unauthenticated attackers to retrieve sensitive audit log data including IP addresses, user IDs, usernames, login/logout events, failed login attempts, and detailed activity descriptions.

PLUGIN Liaison Site Prober

CVE-2026-3569

MEDIUM CVSS 5.3 2026-04-24
Threat Entry Updated 2026-06-17

CVE-2026-3565 - Taqnix Plugin

The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to a missing nonce verification in the taqnix_delete_my_account() function, where the check_ajax_referer() call is explicitly commented out on line 883. This makes it possible for unauthenticated attackers to trick a logged-in non-administrator user into deleting their own account via a forged request granted they can trick the user into performing an action such as clicking a link or visiting a malicious page.

PLUGIN Taqnix

CVE-2026-3565

MEDIUM CVSS 4.3 2026-04-24
Threat Entry Updated 2026-06-17

CVE-2026-5364 - Drag And Drop File Upload For Contact Form 7 Plugin

The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attacker rather than being restricted to administrator-configured values, which when combined with the fact that validation occurs on the unsanitized extension while the file is saved with a sanitized extension, allows special characters like '$' to be stripped during the…

PLUGIN Drag And Drop File Upload For Contact Form 7

CVE-2026-5364

HIGH CVSS 8.1 2026-04-24
Threat Entry Updated 2026-06-17

CVE-2026-5428 - Royal Elementor Addons Plugin

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of esc_attr() for the alt attribute context. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses a page with the malicious image displayed in the media grid widget.

PLUGIN Royal Elementor Addons

CVE-2026-5428

MEDIUM CVSS 6.4 2026-04-24
Threat Entry Updated 2026-06-17

CVE-2026-6810 - Booking Calendar Contact Form Plugin

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to takeover other user's calendars and view user data associated with the calendar.

PLUGIN Booking Calendar Contact Form

CVE-2026-6810

MEDIUM CVSS 5.3 2026-04-24
Threat Entry Updated 2026-06-17

CVE-2026-5347 - Wp Books Gallery Plugin

The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence of capability checks and nonce verification in the admin_init hook that handles the permalink settings update at line 205-209 of wp-books-gallery.php. The vulnerable code checks only for the presence of the 'permalink_structure' POST parameter before updating the 'wbg_cpt_slug' option, without verifying that the request comes from an authenticated administrator. This makes it possible for unauthenticated attackers to modify the custom post type slug for the…

PLUGIN Wp Books Gallery

CVE-2026-5347

MEDIUM CVSS 5.3 2026-04-24
Threat Entry Updated 2026-06-17

CVE-2026-5488 - Google Analytics Dashboard For Wp Plugin

The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin pages (including profile.php which subscribers can access), and while other similar AJAX endpoints in the same class properly check for the exactmetrics_save_settings capability, these two endpoints only verify the nonce. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve valid…

PLUGIN Google Analytics Dashboard For Wp

CVE-2026-5488

MEDIUM CVSS 5.3 2026-04-24
Threat Entry Updated 2026-06-17

CVE-2026-6393 - Betterdocs Plugin

The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying user permissions. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger OpenAI API calls using the site's configured API key with arbitrary user-controlled prompts, leading to unauthorized consumption of the site owner's paid AI API quota.

PLUGIN Betterdocs

CVE-2026-6393

MEDIUM CVSS 4.3 2026-04-24
Threat Entry Updated 2026-06-17

CVE-2026-2028 - MaxiBlocks Builder | 17,000+ Design Assets, Patterns, Icons & Starter Sites Plugin

The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi_remove_custom_image_size' AJAX action in all versions up to, and including, 2.1.8. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files in the wp-content/uploads directory, including files uploaded by other users and administrators.

PLUGIN MaxiBlocks Builder | 17,000+ Design Assets, Patterns, Icons & Starter Sites

CVE-2026-2028

MEDIUM CVSS 5.3 2026-04-24
Threat Entry Updated 2026-06-17

CVE-2026-39440 - FunnelFormsPro Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1.

PLUGIN FunnelFormsPro

CVE-2026-39440

CRITICAL CVSS 9.9 2026-04-23
Threat Entry Updated 2026-06-17

CVE-2026-28040 - Taxi Booking Manager for WooCommerce Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.0.

PLUGIN Taxi Booking Manager for WooCommerce

CVE-2026-28040

MEDIUM CVSS 6.5 2026-04-23
Threat Entry Updated 2026-06-17

CVE-2026-5464 - Google Analytics Dashboard For Wp Plugin

The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due to the reports page exposing the 'onboarding_key' transient to any user with the 'exactmetrics_view_dashboard' capability. This key is the sole authorization gate for the '/wp-json/exactmetrics/v1/onboarding/connect-url' REST endpoint, which returns a one-time hash (OTH) token. This OTH token is then the only credential checked by the 'exactmetrics_connect_process' AJAX endpoint — which has no capability check, no nonce…

PLUGIN Google Analytics Dashboard For Wp

CVE-2026-5464

HIGH CVSS 7.2 2026-04-23
Threat Entry Updated 2026-06-17

CVE-2026-4106 - Ht Mega Addons For Elementor Plugin

The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days

PLUGIN Ht Mega Addons For Elementor

CVE-2026-4106

HIGH CVSS 7.5 2026-04-23
Threat Entry Updated 2026-06-17

CVE-2026-4512 - Recaptcha By Webdesignby Plugin

The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript string context via the grecaptcha_js() function. This allows administrators on multisite installations (who do not have the unfiltered_html capability) to inject arbitrary JavaScript that executes for all visitors to the WordPress login page.

PLUGIN Recaptcha By Webdesignby

CVE-2026-4512

LOW CVSS 3.5 2026-04-23
Threat Entry Updated 2026-06-17

CVE-2026-3361 - Wp Store Locator Plugin

The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta value in versions up to, and including, 2.2.261 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page and opens an injected map marker info window.

PLUGIN Wp Store Locator

CVE-2026-3361

MEDIUM CVSS 6.4 2026-04-23
Threat Entry Updated 2026-06-17

CVE-2026-3844 - Breeze Cache Plugin

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if "Host Files Locally - Gravatars" is enabled, which is disabled by default.

PLUGIN Breeze Cache

CVE-2026-3844

CRITICAL CVSS 9.8 2026-04-23
Scroll to top