Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,226
Critical1,270
High4,357
Medium12,382
Reset
Showing 2701-2720 of 18226 records
Threat Entry Updated 2026-07-24

CVE-2026-39561 - Revive.so Plugin

Missing Authorization vulnerability in WP Chill Revive.so revive-so allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive.so: from n/a through

PLUGIN Revive.so

CVE-2026-39561

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39566 - DirectoryPress Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress directorypress allows Retrieve Embedded Sensitive Data.This issue affects DirectoryPress: from n/a through

PLUGIN DirectoryPress

CVE-2026-39566

MEDIUM CVSS 4.3 2026-04-08
Threat Entry Updated 2026-07-20

CVE-2026-39565 - WpTravelly Plugin

Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through

PLUGIN WpTravelly

CVE-2026-39565

MEDIUM CVSS 4.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39538 - Mikado Core Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Mikado Core mikado-core allows PHP Local File Inclusion.This issue affects Mikado Core: from n/a through

PLUGIN Mikado Core

CVE-2026-39538

HIGH CVSS 7.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39541 - Hydra Booking Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through

PLUGIN Hydra Booking

CVE-2026-39541

MEDIUM CVSS 5.9 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39543 - Tourfic Plugin

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through

PLUGIN Tourfic

CVE-2026-39543

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39542 - Doofinder for WooCommerce Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Doofinder for WooCommerce: from n/a through

PLUGIN Doofinder for WooCommerce

CVE-2026-39542

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39536 - RSVP and Event Management Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Management rsvp allows Retrieve Embedded Sensitive Data.This issue affects RSVP and Event Management: from n/a through

PLUGIN RSVP and Event Management

CVE-2026-39536

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39535 - Display Eventbrite Events Plugin

Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display Eventbrite Events: from n/a through

PLUGIN Display Eventbrite Events

CVE-2026-39535

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39528 - WP Delicious Plugin

Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through

PLUGIN WP Delicious

CVE-2026-39528

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39517 - Blog Filter Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through

PLUGIN Blog Filter

CVE-2026-39517

MEDIUM CVSS 6.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39526 - WpStream Plugin

Authorization Bypass Through User-Controlled Key vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through < 4.11.2.

PLUGIN WpStream

CVE-2026-39526

MEDIUM CVSS 5.4 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39520 - weDocs Plugin

Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weDocs: from n/a through

PLUGIN weDocs

CVE-2026-39520

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39516 - Nexter Blocks Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Retrieve Embedded Sensitive Data.This issue affects Nexter Blocks: from n/a through

PLUGIN Nexter Blocks

CVE-2026-39516

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39509 - Directorist Plugin

Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through

PLUGIN Directorist

CVE-2026-39509

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39521 - Nelio Content Plugin

Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content nelio-content allows Server Side Request Forgery.This issue affects Nelio Content: from n/a through

PLUGIN Nelio Content

CVE-2026-39521

MEDIUM CVSS 4.9 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39510 - Image Photo Gallery Final Tiles Grid Plugin

Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through

PLUGIN Image Photo Gallery Final Tiles Grid

CVE-2026-39510

LOW CVSS 2.7 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39497 - FOX Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Blind SQL Injection.This issue affects FOX: from n/a through

PLUGIN FOX

CVE-2026-39497

HIGH CVSS 7.6 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39508 - Advanced Coupons for WooCommerce Coupons Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-woocommerce-free allows DOM-Based XSS.This issue affects Advanced Coupons for WooCommerce Coupons: from n/a through

PLUGIN Advanced Coupons for WooCommerce Coupons

CVE-2026-39508

MEDIUM CVSS 6.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39500 - Themesflat Addons For Elementor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesflat-addons-for-elementor themesflat-addons-for-elementor allows Stored XSS.This issue affects themesflat-addons-for-elementor: from n/a through

THEME Themesflat Addons For Elementor

CVE-2026-39500

MEDIUM CVSS 6.5 2026-04-08
Scroll to top