Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3281-3300 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-27397 - Really Simple Security Pro Plugin

Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple Security Pro: from n/a through 9.5.4.0.

PLUGIN Really Simple Security Pro

CVE-2026-27397

MEDIUM CVSS 6.5 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-1238 - Wp Slimstat Plugin

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Slimstat

CVE-2026-1238

HIGH CVSS 7.2 2026-03-19
Threat Entry Updated 2026-06-17

CVE-2026-1463 - Nextgen Gallery Plugin

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter in gallery shortcodes. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded…

PLUGIN Nextgen Gallery

CVE-2026-1463

HIGH CVSS 8.8 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-3090 - Post Smtp Plugin

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_type’ parameter in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is only exploitable when the Post SMTP Pro plugin is also installed and its Reporting and…

PLUGIN Post Smtp

CVE-2026-3090

HIGH CVSS 7.2 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-2991 - Kivicare Clinic Management System Plugin

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social provider access token before authenticating a user. This makes it possible for unauthenticated attackers to log in as any patient registered on the system by providing only their email address and an arbitrary value for the access token, bypassing all credential verification. The attacker gains access to sensitive medical records, appointments, prescriptions, and billing…

PLUGIN Kivicare Clinic Management System

CVE-2026-2991

CRITICAL CVSS 9.8 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-2992 - Kivicare Clinic Management System Plugin

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to create a new clinic and a WordPress user with clinic admin privileges.

PLUGIN Kivicare Clinic Management System

CVE-2026-2992

HIGH CVSS 8.2 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-2512 - Simple Embed Code Plugin

The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all versions up to, and including, 2.5.1. This is due to the plugin's sanitization function `sec_check_post_fields()` only running on the `save_post` hook, while WordPress allows custom fields to be added via the `wp_ajax_add_meta` AJAX endpoint without triggering `save_post`. The `ce_filter()` function then outputs these unsanitized meta values directly into page content without escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages…

PLUGIN Simple Embed Code

CVE-2026-2512

MEDIUM CVSS 6.4 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-2559 - Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Plugin

The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the function being hooked to `admin_init` without any `current_user_can()` check or nonce verification. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the site's Office 365 OAuth mail configuration (access token, refresh token, and user email) via a crafted URL. The configuration option is used during wizard setup of Microsoft365…

PLUGIN Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App

CVE-2026-2559

MEDIUM CVSS 5.3 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-25449 - Traveler Plugin

Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through < 3.2.8.1.

PLUGIN Traveler

CVE-2026-25449

CRITICAL CVSS 9.8 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-32565 - Contextual Related Posts Plugin

Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contextual Related Posts: from n/a through < 4.2.2.

PLUGIN Contextual Related Posts

CVE-2026-32565

MEDIUM CVSS 5.3 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-1217 - Duplicate Post Plugin

The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content.

PLUGIN Duplicate Post

CVE-2026-1217

MEDIUM CVSS 5.4 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-3512 - Writeprint Stylometry Plugin

The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter in all versions up to and including 0.1. This is due to insufficient input sanitization and output escaping in the bjl_wprintstylo_comments_nav() function. The function directly outputs the $_GET['p'] parameter into an HTML href attribute without any escaping. This makes it possible for authenticated attackers with Contributor-level permissions or higher to inject arbitrary web scripts in pages that execute if they can successfully trick another user into performing an action such as clicking on…

PLUGIN Writeprint Stylometry

CVE-2026-3512

MEDIUM CVSS 6.1 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-1780 - Paid Link Manager Plugin

The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including, 0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Paid Link Manager

CVE-2026-1780

MEDIUM CVSS 6.1 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-1926 - Subscriptions For Woocommerce Plugin

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. This is due to the function being hooked to the `init` action without any authentication or authorization checks, and only performing a non-empty check on the nonce parameter without actually validating it via `wp_verify_nonce()`. This makes it possible for unauthenticated attackers to cancel any active WooCommerce subscription by sending a crafted GET request with an arbitrary nonce value…

PLUGIN Subscriptions For Woocommerce

CVE-2026-1926

MEDIUM CVSS 5.3 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-4268 - Wp Google Maps Plugin

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_custom_js’ parameter in all versions up to, and including, 10.0.05 due to insufficient input sanitization and output escaping and missing capability check in the 'admin_post_wpgmza_save_settings' hook anonymous function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Google Maps

CVE-2026-4268

MEDIUM CVSS 6.4 2026-03-18
Threat Entry Updated 2026-06-17

CVE-2026-32586 - Booster for WooCommerce Plugin

Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booster for WooCommerce: from n/a through < 7.11.3.

PLUGIN Booster for WooCommerce

CVE-2026-32586

MEDIUM CVSS 5.3 2026-03-17
Threat Entry Updated 2026-06-17

CVE-2026-2373 - Addons And Templates Kit For Elementor Plugin

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_query_args() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract contents of non-public custom post types, such as Contact Form 7 submissions or WooCommerce coupons.

PLUGIN Addons And Templates Kit For Elementor

CVE-2026-2373

MEDIUM CVSS 5.3 2026-03-17
Threat Entry Updated 2026-06-17

CVE-2026-2579 - Product Blocks Plugin

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 4.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Product Blocks

CVE-2026-2579

HIGH CVSS 7.5 2026-03-17
Threat Entry Updated 2026-06-17

CVE-2026-32587 - WP EasyPay Plugin

Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP EasyPay: from n/a through

PLUGIN WP EasyPay

CVE-2026-32587

MEDIUM CVSS 5.4 2026-03-16
Threat Entry Updated 2026-06-17

CVE-2026-32583 - Modern Events Calendar Plugin

Missing Authorization vulnerability in Webnus Inc. Modern Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modern Events Calendar: from n/a through 7.29.0.

PLUGIN Modern Events Calendar

CVE-2026-32583

MEDIUM CVSS 5.3 2026-03-16
Scroll to top