Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 2901-2920 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-32530 - Creator LMS Plugin

Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue affects Creator LMS: from n/a through

PLUGIN Creator LMS

CVE-2026-32530

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32531 - Kunco Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kunco kunco allows PHP Local File Inclusion.This issue affects Kunco: from n/a through < 1.4.5.

PLUGIN Kunco

CVE-2026-32531

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32532 - Elementor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder allows Stored XSS.This issue affects Contact Form & Lead Form Elementor Builder: from n/a through

PLUGIN Elementor

CVE-2026-32532

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32529 - Molla Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in don-themes Molla molla allows Reflected XSS.This issue affects Molla: from n/a through < 1.5.19.

PLUGIN Molla

CVE-2026-32529

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32528 - Riode Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in don-themes Riode riode allows Reflected XSS.This issue affects Riode: from n/a through < 1.6.29.

PLUGIN Riode

CVE-2026-32528

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32533 - LatePoint Plugin

Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LatePoint: from n/a through

PLUGIN LatePoint

CVE-2026-32533

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32525 - JetFormBuilder Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through

PLUGIN JetFormBuilder

CVE-2026-32525

CRITICAL CVSS 9.9 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32523 - WPJAM Basic Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through

PLUGIN WPJAM Basic

CVE-2026-32523

CRITICAL CVSS 9.9 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32524 - Photo Engine Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This issue affects Photo Engine: from n/a through

PLUGIN Photo Engine

CVE-2026-32524

CRITICAL CVSS 9.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32522 - WooCommerce Support Ticket System Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce-support-ticket-system allows Path Traversal.This issue affects WooCommerce Support Ticket System: from n/a through < 18.5.

PLUGIN WooCommerce Support Ticket System

CVE-2026-32522

HIGH CVSS 8.6 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32526 - Abandoned Cart Recovery for WooCommerce Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Stored XSS.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through

PLUGIN Abandoned Cart Recovery for WooCommerce

CVE-2026-32526

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32527 - Contact Form 7 Plugin

Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through

PLUGIN Contact Form 7

CVE-2026-32527

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32520 - RewardsWP Plugin

Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through

PLUGIN RewardsWP

CVE-2026-32520

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32519 - Bit SMTP Plugin

Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through

PLUGIN Bit SMTP

CVE-2026-32519

CRITICAL CVSS 9.0 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32516 - Miraculous Core Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Blind SQL Injection.This issue affects Miraculous Core Plugin: from n/a through < 2.1.2.

PLUGIN Miraculous Core Plugin

CVE-2026-32516

HIGH CVSS 8.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32518 - Gaea Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imithemes Gaea gaea allows Reflected XSS.This issue affects Gaea: from n/a through < 3.8.

PLUGIN Gaea

CVE-2026-32518

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32517 - Contact Manager Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kleor Contact Manager contact-manager allows Reflected XSS.This issue affects Contact Manager: from n/a through

PLUGIN Contact Manager

CVE-2026-32517

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32521 - WP Custom Admin Interface Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows DOM-Based XSS.This issue affects WP Custom Admin Interface: from n/a through

PLUGIN WP Custom Admin Interface

CVE-2026-32521

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32512 - Pelicula Plugin

Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10.

PLUGIN Pelicula

CVE-2026-32512

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32513 - JS Archive List Plugin

Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archive List: from n/a through

PLUGIN JS Archive List

CVE-2026-32513

HIGH CVSS 8.8 2026-03-25
Scroll to top