Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3081-3100 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-24969 - Instant VA Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Instant VA instantva allows Path Traversal.This issue affects Instant VA: from n/a through

PLUGIN Instant VA

CVE-2026-24969

HIGH CVSS 7.7 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24382 - News Magazine X Plugin

Missing Authorization vulnerability in wproyal News Magazine X news-magazine-x allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Magazine X: from n/a through

PLUGIN News Magazine X

CVE-2026-24382

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24391 - Car Dealer Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeMakers Car Dealer cardealer allows Reflected XSS.This issue affects Car Dealer: from n/a through

PLUGIN Car Dealer

CVE-2026-24391

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24964 - Contest Gallery Plugin

Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Server Side Request Forgery.This issue affects Contest Gallery: from n/a through

PLUGIN Contest Gallery

CVE-2026-24964

MEDIUM CVSS 6.4 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24373 - RegistrationMagic Plugin

Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: from n/a through

PLUGIN RegistrationMagic

CVE-2026-24373

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24372 - Subscriptions for WooCommerce Plugin

Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through

PLUGIN Subscriptions for WooCommerce

CVE-2026-24372

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24363 - WP Cost Estimation & Payment Forms Builder Plugin

Missing Authorization vulnerability in loopus WP Cost Estimation & Payment Forms Builder WP_Estimation_Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through < 10.3.0.

PLUGIN WP Cost Estimation & Payment Forms Builder

CVE-2026-24363

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24369 - The Grid Plugin

Missing Authorization vulnerability in Theme-one The Grid the-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Grid: from n/a through < 2.8.0.

PLUGIN The Grid

CVE-2026-24369

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24376 - WPVulnerability Plugin

Missing Authorization vulnerability in Javier Casares WPVulnerability wpvulnerability allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPVulnerability: from n/a through

PLUGIN WPVulnerability

CVE-2026-24376

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24370 - The Grid Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme-one The Grid the-grid allows Stored XSS.This issue affects The Grid: from n/a through < 2.8.0.

PLUGIN The Grid

CVE-2026-24370

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24364 - WP User Frontend Plugin

Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through

PLUGIN WP User Frontend

CVE-2026-24364

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24359 - Dokan Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through

PLUGIN Dokan

CVE-2026-24359

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-23971 - WoodMart Plugin

Deserialization of Untrusted Data vulnerability in xtemos WoodMart woodmart allows Object Injection.This issue affects WoodMart: from n/a through

PLUGIN WoodMart

CVE-2026-23971

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-23977 - Helpdesk Support Ticket System for WooCommerce Plugin

Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through

PLUGIN Helpdesk Support Ticket System for WooCommerce

CVE-2026-23977

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-23979 - Gyan Elements Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softwebmedia Gyan Elements gyan-elements allows Reflected XSS.This issue affects Gyan Elements: from n/a through

PLUGIN Gyan Elements

CVE-2026-23979

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-23973 - Golo Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through < 1.7.5.

PLUGIN Golo

CVE-2026-23973

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-23807 - WP Telegram Widget and Join Link Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Socio WP Telegram Widget and Join Link wptelegram-widget allows Reflected XSS.This issue affects WP Telegram Widget and Join Link: from n/a through

PLUGIN WP Telegram Widget and Join Link

CVE-2026-23807

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-23972 - Booking and Rental Manager Plugin

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through

PLUGIN Booking and Rental Manager

CVE-2026-23972

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24362 - Ultimate Post Kit Plugin

Missing Authorization vulnerability in bdthemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Post Kit: from n/a through

PLUGIN Ultimate Post Kit

CVE-2026-24362

MEDIUM CVSS 6.4 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-23806 - Jobs for WordPress Plugin

Missing Authorization vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Jobs for WordPress: from n/a through

PLUGIN Jobs for WordPress

CVE-2026-23806

HIGH CVSS 7.5 2026-03-25
Scroll to top