Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,226
Critical1,270
High4,357
Medium12,382
Reset
Showing 2681-2700 of 18226 records
Threat Entry Updated 2026-07-24

CVE-2026-39609 - Wava Payment Plugin

Missing Authorization vulnerability in Wava.co Wava Payment wava-payment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wava Payment: from n/a through

PLUGIN Wava Payment

CVE-2026-39609

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39608 - iPOSpays Gateways WC Plugin

Missing Authorization vulnerability in iPOSPays iPOSpays Gateways WC ipospays-gateways-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iPOSpays Gateways WC: from n/a through

PLUGIN iPOSpays Gateways WC

CVE-2026-39608

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39604 - MyBookTable Bookstore Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through

PLUGIN MyBookTable Bookstore

CVE-2026-39604

MEDIUM CVSS 5.9 2026-04-08
Threat Entry Updated 2026-07-20

CVE-2026-39603 - Grand Photography Plugin

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects Grand Photography: from n/a through

PLUGIN Grand Photography

CVE-2026-39603

MEDIUM CVSS 5.4 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39606 - BizReview Plugin

Missing Authorization vulnerability in Foysal Imran BizReview bizreview allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BizReview: from n/a through

PLUGIN BizReview

CVE-2026-39606

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39605 - Super Custom Login Plugin

Missing Authorization vulnerability in Obadiah Super Custom Login super-custom-login allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Custom Login: from n/a through

PLUGIN Super Custom Login

CVE-2026-39605

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39602 - Order Tracking Plugin

Missing Authorization vulnerability in Rustaurius Order Tracking order-tracking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Tracking: from n/a through

PLUGIN Order Tracking

CVE-2026-39602

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39588 - NM Gift Registry and Wishlist Lite Plugin

Missing Authorization vulnerability in nmerii NM Gift Registry and Wishlist Lite nm-gift-registry-and-wishlist-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NM Gift Registry and Wishlist Lite: from n/a through

PLUGIN NM Gift Registry and Wishlist Lite

CVE-2026-39588

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39592 - DEPART Plugin

Missing Authorization vulnerability in Andy Ha DEPART depart-deposit-and-part-payment-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DEPART: from n/a through

PLUGIN DEPART

CVE-2026-39592

MEDIUM CVSS 4.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39575 - Custom Query Blocks Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query Blocks: from n/a through

PLUGIN Custom Query Blocks

CVE-2026-39575

MEDIUM CVSS 6.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39569 - 12 Step Meeting List Plugin

Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 12 Step Meeting List: from n/a through

PLUGIN 12 Step Meeting List

CVE-2026-39569

MEDIUM CVSS 6.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39586 - RepairBuddy Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through

PLUGIN RepairBuddy

CVE-2026-39586

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39585 - Booktics Plugin

Missing Authorization vulnerability in Arraytics Booktics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Booktics: from n/a through 1.0.16.

PLUGIN Booktics

CVE-2026-39585

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39571 - Instantio Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themefic Instantio instantio allows Retrieve Embedded Sensitive Data.This issue affects Instantio: from n/a through

PLUGIN Instantio

CVE-2026-39571

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39570 - 12 Step Meeting List Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through

PLUGIN 12 Step Meeting List

CVE-2026-39570

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39572 - Bus Ticket Booking with Seat Reservation Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Retrieve Embedded Sensitive Data.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through < 5.6.5.

PLUGIN Bus Ticket Booking with Seat Reservation

CVE-2026-39572

MEDIUM CVSS 4.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39544 - LabtechCO Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek LabtechCO labtechco allows PHP Local File Inclusion.This issue affects LabtechCO: from n/a through

PLUGIN LabtechCO

CVE-2026-39544

HIGH CVSS 7.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39564 - Sunshine Photo Cart Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Retrieve Embedded Sensitive Data.This issue affects Sunshine Photo Cart: from n/a through < 3.6.2.

PLUGIN Sunshine Photo Cart

CVE-2026-39564

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39563 - Share This Image Plugin

Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through

PLUGIN Share This Image

CVE-2026-39563

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39562 - Client Invoicing by Sprout Invoices Plugin

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through

PLUGIN Client Invoicing by Sprout Invoices

CVE-2026-39562

MEDIUM CVSS 5.3 2026-04-08
Scroll to top