Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,226
Critical1,270
High4,357
Medium12,382
Reset
Showing 2661-2680 of 18226 records
Threat Entry Updated 2026-07-24

CVE-2026-39631 - WPSchoolPress Plugin

Missing Authorization vulnerability in Ronik@UnlimitedWP WPSchoolPress wpschoolpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSchoolPress: from n/a through

PLUGIN WPSchoolPress

CVE-2026-39631

MEDIUM CVSS 4.9 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39627 - Ashe Plugin

Missing Authorization vulnerability in wproyal Ashe ashe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe: from n/a through

PLUGIN Ashe

CVE-2026-39627

MEDIUM CVSS 4.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39620 - Appointment Plugin

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through

PLUGIN Appointment

CVE-2026-39620

CRITICAL CVSS 9.6 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39621 - SpicePress Plugin

Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through

PLUGIN SpicePress

CVE-2026-39621

HIGH CVSS 8.8 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39623 - Biolife Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Biolife biolife allows PHP Local File Inclusion.This issue affects Biolife: from n/a through

PLUGIN Biolife

CVE-2026-39623

HIGH CVSS 7.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39626 - Armania Plugin

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes Armania armania allows Code Injection.This issue affects Armania: from n/a through

PLUGIN Armania

CVE-2026-39626

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39625 - TechOne Plugin

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes TechOne techone allows Code Injection.This issue affects TechOne: from n/a through

PLUGIN TechOne

CVE-2026-39625

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39624 - Biolife Plugin

Missing Authorization vulnerability in kutethemes Biolife biolife allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Biolife: from n/a through

PLUGIN Biolife

CVE-2026-39624

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39622 - Education Base Plugin

Missing Authorization vulnerability in acmethemes Education Base education-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education Base: from n/a through

PLUGIN Education Base

CVE-2026-39622

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39619 - Busiprof Plugin

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Busiprof: from n/a through

PLUGIN Busiprof

CVE-2026-39619

CRITICAL CVSS 9.6 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39617 - Bluestreet Plugin

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through

PLUGIN Bluestreet

CVE-2026-39617

CRITICAL CVSS 9.6 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39613 - Boutique Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Boutique kute-boutique allows PHP Local File Inclusion.This issue affects Boutique: from n/a through

PLUGIN Boutique

CVE-2026-39613

HIGH CVSS 7.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39615 - Download Manager Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Download Manager download-manager allows Stored XSS.This issue affects Download Manager: from n/a through

PLUGIN Download Manager

CVE-2026-39615

MEDIUM CVSS 5.9 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39614 - JW Player for WordPress Plugin

Missing Authorization vulnerability in ilGhera JW Player for WordPress jw-player-7-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JW Player for WordPress: from n/a through

PLUGIN JW Player for WordPress

CVE-2026-39614

MEDIUM CVSS 5.4 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39616 - Download Attachments Plugin

Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Attachments: from n/a through

PLUGIN Download Attachments

CVE-2026-39616

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39618 - NewsExo Plugin

Cross-Site Request Forgery (CSRF) vulnerability in themearile NewsExo newsexo allows Cross Site Request Forgery.This issue affects NewsExo: from n/a through

PLUGIN NewsExo

CVE-2026-39618

MEDIUM CVSS 4.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39611 - KuteShop Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes KuteShop kuteshop allows PHP Local File Inclusion.This issue affects KuteShop: from n/a through

PLUGIN KuteShop

CVE-2026-39611

HIGH CVSS 7.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39607 - Filter Plus Plugin

Missing Authorization vulnerability in Wpbens Filter Plus filter-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filter Plus: from n/a through

PLUGIN Filter Plus

CVE-2026-39607

MEDIUM CVSS 5.4 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39612 - KuteShop Plugin

Missing Authorization vulnerability in kutethemes KuteShop kuteshop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KuteShop: from n/a through

PLUGIN KuteShop

CVE-2026-39612

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39610 - WpXmas-Snow Plugin

Missing Authorization vulnerability in Pankaj Kumar WpXmas-Snow wpxmas-snow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpXmas-Snow: from n/a through

PLUGIN WpXmas-Snow

CVE-2026-39610

MEDIUM CVSS 5.3 2026-04-08
Scroll to top