Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,226
Critical1,270
High4,357
Medium12,382
Reset
Showing 2721-2740 of 18226 records
Threat Entry Updated 2026-07-24

CVE-2026-39504 - InstaWP Connect Plugin

Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through

PLUGIN InstaWP Connect

CVE-2026-39504

MEDIUM CVSS 5.4 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39505 - Seriously Simple Podcasting Plugin

Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through

PLUGIN Seriously Simple Podcasting

CVE-2026-39505

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39501 - FOX Plugin

Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FOX: from n/a through

PLUGIN FOX

CVE-2026-39501

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39506 - AI Engine (Pro Plugin

Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Engine (Pro): from n/a through < 3.4.2.

PLUGIN AI Engine (Pro

CVE-2026-39506

MEDIUM CVSS 4.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39495 - Simply Schedule Appointments Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through

PLUGIN Simply Schedule Appointments

CVE-2026-39495

HIGH CVSS 8.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39486 - Download Monitor Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download Monitor download-monitor allows Blind SQL Injection.This issue affects Download Monitor: from n/a through

PLUGIN Download Monitor

CVE-2026-39486

HIGH CVSS 8.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39496 - YayMail Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayMail yaymail allows Blind SQL Injection.This issue affects YayMail: from n/a through

PLUGIN YayMail

CVE-2026-39496

HIGH CVSS 7.6 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39487 - Amelia Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through

PLUGIN Amelia

CVE-2026-39487

HIGH CVSS 7.6 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39488 - SureCart Plugin

Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a through

PLUGIN SureCart

CVE-2026-39488

MEDIUM CVSS 6.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39484 - Hide My WP Ghost Plugin

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phishing.This issue affects Hide My WP Ghost: from n/a through < 7.0.00.

PLUGIN Hide My WP Ghost

CVE-2026-39484

MEDIUM CVSS 4.7 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39485 - Youtube Embed Plus Plugin

Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Embed Plus: from n/a through

PLUGIN Youtube Embed Plus

CVE-2026-39485

MEDIUM CVSS 4.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39479 - OttoKit Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force OttoKit suretriggers allows Blind SQL Injection.This issue affects OttoKit: from n/a through

PLUGIN OttoKit

CVE-2026-39479

HIGH CVSS 7.6 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39475 - User Feedback Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through

PLUGIN User Feedback

CVE-2026-39475

HIGH CVSS 7.6 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39483 - VK All in One Expansion Unit Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit vk-all-in-one-expansion-unit allows Stored XSS.This issue affects VK All in One Expansion Unit: from n/a through

PLUGIN VK All in One Expansion Unit

CVE-2026-39483

MEDIUM CVSS 6.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39482 - Post Expirator Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post Expirator post-expirator allows DOM-Based XSS.This issue affects Post Expirator: from n/a through

PLUGIN Post Expirator

CVE-2026-39482

MEDIUM CVSS 6.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39473 - Simple History Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Pär Thernström Simple History simple-history allows Retrieve Embedded Sensitive Data.This issue affects Simple History: from n/a through

PLUGIN Simple History

CVE-2026-39473

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-20

CVE-2026-39477 - CartFlows Plugin

Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartFlows: from n/a through

PLUGIN CartFlows

CVE-2026-39477

MEDIUM CVSS 4.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39476 - User Feedback Plugin

Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through

PLUGIN User Feedback

CVE-2026-39476

MEDIUM CVSS 4.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39466 - Broken Link Checker Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Broken Link Checker broken-link-checker allows Blind SQL Injection.This issue affects Broken Link Checker: from n/a through

PLUGIN Broken Link Checker

CVE-2026-39466

HIGH CVSS 7.6 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39464 - Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin

Server-Side Request Forgery (SSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Server Side Request Forgery.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through

PLUGIN Coming Soon Page, Under Construction & Maintenance Mode by SeedProd

CVE-2026-39464

MEDIUM CVSS 5.5 2026-04-08
Scroll to top