Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,226
Critical1,270
High4,357
Medium12,382
Reset
Showing 2781-2800 of 18226 records
Threat Entry Updated 2026-06-17

CVE-2026-34903 - Ocean Extra Plugin

Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through 2.5.3.

PLUGIN Ocean Extra

CVE-2026-34903

MEDIUM CVSS 5.4 2026-04-07
Threat Entry Updated 2026-06-17

CVE-2026-34899 - LTL Freight Quotes – Worldwide Express Edition Plugin

Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.

PLUGIN LTL Freight Quotes – Worldwide Express Edition

CVE-2026-34899

MEDIUM CVSS 5.3 2026-04-07
Threat Entry Updated 2026-06-17

CVE-2026-3177 - Donation Plugin

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic verification of incoming Stripe webhook events. This makes it possible for unauthenticated attackers to forge payment_intent.succeeded webhook payloads and mark pending donations as completed without a real payment.

PLUGIN Donation

CVE-2026-3177

MEDIUM CVSS 5.3 2026-04-07
Threat Entry Updated 2026-06-17

CVE-2026-5465 - Ameliabooking Plugin

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Employee) user updates their own profile. The `externalId` maps directly to a WordPress user ID and is passed to `wp_set_password()` and `wp_update_user()` without authorization checks. This makes it possible for authenticated attackers, with Provider-level (Employee) access and above, to take over any WordPress account — including…

PLUGIN Ameliabooking

CVE-2026-5465

HIGH CVSS 8.8 2026-04-07
Threat Entry Updated 2026-06-17

CVE-2026-4079 - Sql Chart Builder Plugin

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

PLUGIN Sql Chart Builder

CVE-2026-4079

MEDIUM CVSS 6.5 2026-04-07
Threat Entry Updated 2026-06-17

CVE-2026-0740 - Ninja Forms File Uploads Plugin

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability was partially patched in version 3.3.25 and fully patched in version 3.3.27.

PLUGIN Ninja Forms File Uploads

CVE-2026-0740

CRITICAL CVSS 9.8 2026-04-07
Threat Entry Updated 2026-06-17

CVE-2026-34885 - Media LIbrary Assistant Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a through 3.34.

PLUGIN Media LIbrary Assistant

CVE-2026-34885

HIGH CVSS 8.5 2026-04-06
Threat Entry Updated 2026-06-17

CVE-2026-34897 - Media LIbrary Assistant Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.34.

PLUGIN Media LIbrary Assistant

CVE-2026-34897

MEDIUM CVSS 6.5 2026-04-06
Threat Entry Updated 2026-07-24

CVE-2026-3666 - Wpforo Forum Plugin

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server by embedding a crafted path traversal string in a forum post body and then deleting the post.

PLUGIN Wpforo Forum

CVE-2026-3666

HIGH CVSS 8.8 2026-04-04
Threat Entry Updated 2026-07-24

CVE-2026-2936 - Visitor Traffic Real Time Statistics Plugin

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an admin user accesses the Traffic by Title section.

PLUGIN Visitor Traffic Real Time Statistics

CVE-2026-2936

HIGH CVSS 7.2 2026-04-04
Threat Entry Updated 2026-07-24

CVE-2026-3309 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due to the plugin allowing user-supplied billing field values from the checkout process to be interpolated into shortcode template strings that are subsequently processed without proper sanitization of shortcode syntax. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes by submitting crafted billing field values during the checkout process.

PLUGIN Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

CVE-2026-3309

MEDIUM CVSS 6.5 2026-04-04
Threat Entry Updated 2026-07-21

CVE-2026-1233 - Text to Speech – TTSWP Plugin

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_TTS_Remote_Telemetry` class. This makes it possible for unauthenticated attackers to extract and decode these credentials, gaining unauthorized write access to the vendor's telemetry database.

PLUGIN Text to Speech – TTSWP

CVE-2026-1233

HIGH CVSS 7.5 2026-04-04
Threat Entry Updated 2026-07-24

CVE-2026-0626 - WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell Plugin

The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping of the 'button_icon' parameter. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

CVE-2026-0626

MEDIUM CVSS 6.4 2026-04-04
Threat Entry Updated 2026-07-24

CVE-2026-5425 - Widgets For Social Photo Feed Plugin

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Widgets For Social Photo Feed

CVE-2026-5425

HIGH CVSS 7.2 2026-04-04
Threat Entry Updated 2026-07-21

CVE-2026-3445 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on the `change_plan_sub_id` parameter in the `process_checkout()` function. This makes it possible for authenticated attackers, with subscriber level access and above, to reference another user's active subscription during checkout to manipulate proration calculations, allowing them to obtain paid lifetime membership plans without payment via the `ppress_process_checkout` AJAX…

PLUGIN Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

CVE-2026-3445

HIGH CVSS 7.1 2026-04-04
Threat Entry Updated 2026-07-24

CVE-2026-2437 - Tour Operator Software Plugin

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, and including, 6.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tour Operator Software

CVE-2026-2437

MEDIUM CVSS 6.4 2026-04-04
Threat Entry Updated 2026-07-21

CVE-2026-2826 - Kadence Blocks Plugin

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user has the `upload_files` capability in the `process_pattern` REST API endpoint. This makes it possible for authenticated attackers, with contributor level access and above, to upload images to the WordPress Media Library by supplying remote image URLs that the server downloads and creates as media attachments.

PLUGIN Kadence Blocks

CVE-2026-2826

MEDIUM CVSS 4.3 2026-04-04
Scroll to top