Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3121-3140 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-22498 - Laurent Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent laurent allows PHP Local File Inclusion.This issue affects Laurent: from n/a through

PLUGIN Laurent

CVE-2026-22498

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-22496 - Hypnotherapy Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Hypnotherapy hypnotherapy allows PHP Local File Inclusion.This issue affects Hypnotherapy: from n/a through

PLUGIN Hypnotherapy

CVE-2026-22496

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-22495 - Greenville Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Greenville greenville allows PHP Local File Inclusion.This issue affects Greenville: from n/a through

PLUGIN Greenville

CVE-2026-22495

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-22494 - Good Homes Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Good Homes good-homes allows PHP Local File Inclusion.This issue affects Good Homes: from n/a through

PLUGIN Good Homes

CVE-2026-22494

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-22493 - Gaspard Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Gaspard gaspard allows PHP Local File Inclusion.This issue affects Gaspard: from n/a through

PLUGIN Gaspard

CVE-2026-22493

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-22491 - My auctions allegro Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Reflected XSS.This issue affects My auctions allegro: from n/a through

PLUGIN My auctions allegro

CVE-2026-22491

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-22484 - Lisfinity Core Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL Injection.This issue affects Lisfinity Core: from n/a through

PLUGIN Lisfinity Core

CVE-2026-22484

CRITICAL CVSS 9.3 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-22448 - PitchPrint Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in flexcubed PitchPrint pitchprint allows Path Traversal.This issue affects PitchPrint: from n/a through

PLUGIN PitchPrint

CVE-2026-22448

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-22480 - Product Feed for WooCommerce Plugin

Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Object Injection.This issue affects Product Feed for WooCommerce: from n/a through

PLUGIN Product Feed for WooCommerce

CVE-2026-22480

HIGH CVSS 7.2 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-22485 - My Album Gallery Plugin

Missing Authorization vulnerability in Ruhul Amin My Album Gallery my-album-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Album Gallery: from n/a through

PLUGIN My Album Gallery

CVE-2026-22485

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-23395 - WordPress component

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ Currently the code attempts to accept requests regardless of the command identifier which may cause multiple requests to be marked as pending (FLAG_DEFER_SETUP) which can cause more than L2CAP_ECRED_MAX_CID(5) to be allocated in l2cap_ecred_rsp_defer causing an overflow. The spec is quite clear that the same identifier shall not be used on subsequent requests: 'Within each signaling channel a different Identifier shall be used for each successive request or indication.' https://www.bluetooth.com/wp-content/uploads/Files/Specification/HTML/Core-62/out/en/host/logical-link-control-and-adaptation-protocol-specification.html#UUID-32a25a06-4aa4-c6c7-77c5-dcfe3682355d So this attempts to…

UNKNOWN WordPress component

CVE-2026-23395

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-2343 - Peprodev Ultimate Invoice Plugin

The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP archives containing exported invoice PDFs. The ZIP files are named predictably making it possible to brute force and retreive PII.

PLUGIN Peprodev Ultimate Invoice

CVE-2026-2343

MEDIUM CVSS 5.3 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-4766 - Easy Image Gallery Plugin

The Easy Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery shortcode post meta field in all versions up to, and including, 1.5.3. This is due to insufficient input sanitization and output escaping on user-supplied gallery shortcode values. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Image Gallery

CVE-2026-4766

MEDIUM CVSS 6.4 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-4662 - Jet Engine Plugin

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled input to bypass security checks) combined with the `prepare_where_clause()` method in the SQL Query Builder not sanitizing the `compare` operator before concatenating it into SQL statements. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from…

PLUGIN Jet Engine

CVE-2026-4662

HIGH CVSS 7.5 2026-03-24
Threat Entry Updated 2026-06-17

CVE-2026-4283 - Shapepress Dsgvo Plugin

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirmation flow and immediately triggers irreversible account anonymization. This makes it possible for unauthenticated attackers to permanently destroy any non-administrator user account (password randomized, username/email overwritten, roles stripped, comments anonymized, sensitive usermeta wiped) by submitting the victim's email address with `process_now=1`. The nonce required for the request is publicly…

PLUGIN Shapepress Dsgvo

CVE-2026-4283

CRITICAL CVSS 9.1 2026-03-24
Threat Entry Updated 2026-06-17

CVE-2026-3138 - Product Filter For Woocommerce By Wbw Plugin

The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versions up to, and including, 3.1.2. This is due to the plugin's MVC framework dynamically registering unauthenticated AJAX handlers via `wp_ajax_nopriv_` hooks without verifying user capabilities, combined with the base controller's `__call()` magic method forwarding undefined method calls to the model layer, and the `havePermissions()` method defaulting to `true` when no permissions are explicitly defined. This makes it possible for unauthenticated attackers to truncate the plugin's…

PLUGIN Product Filter For Woocommerce By Wbw

CVE-2026-3138

MEDIUM CVSS 6.5 2026-03-24
Threat Entry Updated 2026-06-17

CVE-2026-3079 - Learndash Lms Plugin

The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' parameter in the 'learndash_propanel_template' AJAX action in all versions up to, and including, 5.0.3. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Learndash Lms

CVE-2026-3079

MEDIUM CVSS 6.5 2026-03-24
Threat Entry Updated 2026-06-17

CVE-2026-33290 - Wp Graphql Plugin

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.10.0, an authorization flaw in updateComment allows an authenticated low-privileged user (including a custom role with zero capabilities) to change moderation status of their own comment (for example to APPROVE) without the moderate_comments capability. This can bypass moderation workflows and let untrusted users self-approve content. Version 2.10.0 contains a patch. ### Details In WPGraphQL 2.9.1 (tested), authorization for updateComment is owner-based, not field-based: - plugins/wp-graphql/src/Mutation/CommentUpdate.php:92 allows moderators. - plugins/wp-graphql/src/Mutation/CommentUpdate.php:99:99 also allows the comment owner, even if they lack moderation…

PLUGIN Wp Graphql

CVE-2026-33290

MEDIUM CVSS 4.3 2026-03-24
Threat Entry Updated 2026-06-17

CVE-2026-4001 - Woocommerce Custom Product Addons Pro Plugin

The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_custom_formula() function within includes/process/price.php. This is due to insufficient sanitization and validation of user-submitted field values before passing them to PHP's eval() function. The sanitize_values() method strips HTML tags but does not escape single quotes or prevent PHP code injection. This makes it possible for unauthenticated attackers to execute arbitrary code on the server by submitting a crafted value…

PLUGIN Woocommerce Custom Product Addons Pro

CVE-2026-4001

CRITICAL CVSS 9.8 2026-03-24
Threat Entry Updated 2026-06-17

CVE-2026-4021 - Contest Gallery Plugin

The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email string in a `WHERE ID = %s` clause instead of the numeric user ID, combined with an unauthenticated key-based login endpoint in `ajax-functions-frontend.php`. When the non-default `RegMailOptional=1` setting is enabled, an attacker can register with a crafted email starting with the target user ID (e.g., `1poc@example.test`), trigger the confirmation flow to…

PLUGIN Contest Gallery

CVE-2026-4021

HIGH CVSS 8.1 2026-03-24
Scroll to top