Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3261-3280 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-25445 - WishList Member X Plugin

Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a through 3.29.0.

PLUGIN WishList Member X

CVE-2026-25445

HIGH CVSS 8.8 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-25443 - Fraud Prevention For Woocommerce Plugin

Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fraud Prevention For Woocommerce: from n/a through

PLUGIN Fraud Prevention For Woocommerce

CVE-2026-25443

HIGH CVSS 7.5 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-25442 - Kentha Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kentha kentha allows Reflected XSS.This issue affects Kentha: from n/a through

PLUGIN Kentha

CVE-2026-25442

HIGH CVSS 7.1 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-25438 - Gutenberg Blocks Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks allows Reflected XSS.This issue affects Gutenberg Blocks: from n/a through

PLUGIN Gutenberg Blocks

CVE-2026-25438

HIGH CVSS 7.1 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-25471 - Admin Safety Guard Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-guard allows Password Recovery Exploitation.This issue affects Admin Safety Guard: from n/a through

PLUGIN Admin Safety Guard

CVE-2026-25471

HIGH CVSS 8.1 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-3475 - Instant Popup Builder Plugin

The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all versions up to and including 1.1.7. This is due to the handle_email_verification_page() function constructing a shortcode string from user-supplied GET parameters (token, email) and passing it to do_shortcode() without properly sanitizing square bracket characters, combined with missing authorization checks on the init hook. While sanitize_text_field() and esc_attr() are applied, neither function strips or escapes square bracket characters ([ and ]). WordPress's shortcode regex uses [^\]\/]* to match content inside shortcode tags, meaning a ]…

PLUGIN Instant Popup Builder

CVE-2026-3475

MEDIUM CVSS 5.3 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-25312 - EventPrime Plugin

Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through

PLUGIN EventPrime

CVE-2026-25312

HIGH CVSS 7.5 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-4120 - Info Cards Plugin

The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btnUrl' parameter within the Info Cards block in all versions up to, and including, 2.0.7. This is due to insufficient input validation on URL schemes, specifically the lack of javascript: protocol filtering. The block's render.php passes all attributes as JSON to the frontend via a data-attributes HTML attribute using esc_attr(wp_json_encode()), which prevents HTML attribute injection but does not validate URL protocols within the JSON data. The client-side view.js…

PLUGIN Info Cards

CVE-2026-4120

MEDIUM CVSS 6.4 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-4068 - Add Custom Fields To Media Plugin

The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.3. This is due to missing nonce validation on the field deletion functionality in the admin display template. The plugin properly validates a nonce for the 'add field' operation (line 24-36), but the 'delete field' operation (lines 38-49) processes the $_GET['delete'] parameter and calls update_option() without any nonce verification. This makes it possible for unauthenticated attackers to delete arbitrary custom media fields via a forged request, granted they…

PLUGIN Add Custom Fields To Media

CVE-2026-4068

MEDIUM CVSS 4.3 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-27093 - Tripgo Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Tripgo tripgo allows PHP Local File Inclusion.This issue affects Tripgo: from n/a through < 1.5.6.

PLUGIN Tripgo

CVE-2026-27093

HIGH CVSS 8.1 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-4006 - Simple Draft List Plugin

The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta (Custom Field) in all versions up to and including 2.6.2. This is due to insufficient input sanitization and output escaping on the author display name when no author URL is present. The plugin accesses `$draft_data->display_name` which, because `display_name` is not a native WP_Post property, triggers WP_Post::__get() and resolves to `get_post_meta($post_id, 'display_name', true)`. When the `user_url` meta field is empty, the `$author` value is assigned to `$author_link` on line 383 without any escaping…

PLUGIN Simple Draft List

CVE-2026-4006

MEDIUM CVSS 6.4 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-2571 - Download Manager Plugin

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive information for any user on the site including email addresses, display names, and registration dates.

PLUGIN Download Manager

CVE-2026-2571

MEDIUM CVSS 4.3 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-27091 - UiPress lite Plugin

Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UiPress lite: from n/a through

PLUGIN UiPress lite

CVE-2026-27091

MEDIUM CVSS 6.3 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-28073 - WP eMember Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ WP eMember allows Reflected XSS.This issue affects WP eMember: from n/a through v10.2.2.

PLUGIN WP eMember

CVE-2026-28073

HIGH CVSS 7.1 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-28044 - WP Rocket Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket allows Stored XSS.This issue affects WP Rocket: from n/a through 3.19.4.

PLUGIN WP Rocket

CVE-2026-28044

MEDIUM CVSS 5.9 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-28070 - WP eMember Plugin

Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP eMember: from n/a through v10.2.2.

PLUGIN WP eMember

CVE-2026-28070

MEDIUM CVSS 5.3 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-27542 - Woocommerce Wholesale Lead Capture Plugin

Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a through

PLUGIN Woocommerce Wholesale Lead Capture

CVE-2026-27542

CRITICAL CVSS 9.8 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-27413 - Profile Builder Pro Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0.

PLUGIN Profile Builder Pro

CVE-2026-27413

CRITICAL CVSS 9.3 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-27540 - Woocommerce Wholesale Lead Capture Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through

PLUGIN Woocommerce Wholesale Lead Capture

CVE-2026-27540

CRITICAL CVSS 9.0 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-27096 - Allows Object Injection Theme

Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme colorfolio allows Object Injection.This issue affects ColorFolio - Freelance Designer WordPress Theme: from n/a through

THEME Allows Object Injection

CVE-2026-27096

HIGH CVSS 8.1 2026-03-19
Scroll to top