Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3301-3320 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-25369 - Flexmls® IDX Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Reflected XSS.This issue affects Flexmls® IDX: from n/a through

PLUGIN Flexmls® IDX

CVE-2026-25369

HIGH CVSS 7.1 2026-03-16
Threat Entry Updated 2026-06-17

CVE-2026-2233 - User Registration Plugin

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to modify arbitrary posts (e.g. unpublish published posts and overwrite the contents) via the 'post_id' parameter.

PLUGIN User Registration

CVE-2026-2233

MEDIUM CVSS 5.3 2026-03-16
Threat Entry Updated 2026-06-17

CVE-2026-1947 - Ultimate Forms Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the submit_nex_form() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to to overwrite arbitrary form entries via the 'nf_set_entry_update_id' parameter.

PLUGIN Ultimate Forms

CVE-2026-1947

HIGH CVSS 7.5 2026-03-16
Threat Entry Updated 2026-06-17

CVE-2026-1948 - Ultimate Forms Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function in all versions up to, and including, 9.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to to deactivate the plugin license.

PLUGIN Ultimate Forms

CVE-2026-1948

MEDIUM CVSS 4.3 2026-03-16
Threat Entry Updated 2026-06-17

CVE-2026-1883 - And Custom Post Types Plugin

The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary folders created by other users.

PLUGIN And Custom Post Types

CVE-2026-1883

MEDIUM CVSS 4.3 2026-03-16
Threat Entry Updated 2026-06-17

CVE-2026-1870 - Widgets For Elementor Plugin

The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing validation checks on the 'thim-ekit/archive-course/get-courses' REST endpoint callback function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to disclose private or draft LearnPress course content by supplying post_status in the params_url payload.

PLUGIN Widgets For Elementor

CVE-2026-1870

MEDIUM CVSS 5.3 2026-03-16
Threat Entry Updated 2026-06-17

CVE-2026-4063 - Social Icons Widget By Wpzoom Plugin

The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() method hooked to admin_menu in all versions up to, and including, 4.5.8. This is due to the method performing wp_insert_post() and update_post_meta() calls to create a sharing configuration without verifying the current user has administrator-level capabilities. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger the creation of a published wpzoom-sharing configuration post with default sharing button settings, which…

PLUGIN Social Icons Widget By Wpzoom

CVE-2026-4063

MEDIUM CVSS 4.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-3986 - Calculated Fields Form Plugin

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in all versions up to, and including, 5.4.5.0. This is due to insufficient capability checks on the form settings save handler and insufficient input sanitization of the `fcontent` field in `fhtml` field types. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Calculated Fields Form

CVE-2026-3986

MEDIUM CVSS 6.4 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-3891 - Pix For Woocommerce Plugin

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Pix For Woocommerce

CVE-2026-3891

CRITICAL CVSS 9.8 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-3045 - Simply Schedule Appointments Plugin

The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due to two compounding weaknesses: (1) a non-user-bound `public_nonce` is exposed to unauthenticated users through the public `/wp-json/ssa/v1/embed-inner` REST endpoint, and (2) the `get_item()` method in `SSA_Settings_Api` relies on `nonce_permissions_check()` for authorization (which accepts the public nonce) but does not call `remove_unauthorized_settings_for_current_user()` to filter restricted fields. This makes it possible for unauthenticated attackers to access admin-only plugin settings including the administrator…

PLUGIN Simply Schedule Appointments

CVE-2026-3045

HIGH CVSS 7.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32543 - Responsive Blocks Plugin

Missing Authorization vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Blocks: from n/a through

PLUGIN Responsive Blocks

CVE-2026-32543

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32487 - Lawyer Landing Page Plugin

Missing Authorization vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lawyer Landing Page: from n/a through

PLUGIN Lawyer Landing Page

CVE-2026-32487

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32459 - UpsellWP Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Blind SQL Injection.This issue affects UpsellWP: from n/a through

PLUGIN UpsellWP

CVE-2026-32459

HIGH CVSS 7.6 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32458 - WOLF Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 WOLF bulk-editor allows Blind SQL Injection.This issue affects WOLF: from n/a through

PLUGIN WOLF

CVE-2026-32458

HIGH CVSS 7.6 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32460 - Contact Form 7 Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-32460

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32462 - Elementor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Master Addons for Elementor master-addons allows DOM-Based XSS.This issue affects Master Addons for Elementor: from n/a through

PLUGIN Elementor

CVE-2026-32462

MEDIUM CVSS 5.9 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32486 - Travel Booking Plugin

Missing Authorization vulnerability in wptravelengine Travel Booking travel-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Booking: from n/a through

PLUGIN Travel Booking

CVE-2026-32486

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32461 - Really Simple SSL Plugin

Missing Authorization vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple SSL: from n/a through

PLUGIN Really Simple SSL

CVE-2026-32461

MEDIUM CVSS 4.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32455 - MDTF Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows DOM-Based XSS.This issue affects MDTF: from n/a through

PLUGIN MDTF

CVE-2026-32455

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32454 - Avada Core Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Avada Core fusion-core allows DOM-Based XSS.This issue affects Avada Core: from n/a through < 5.15.0.

PLUGIN Avada Core

CVE-2026-32454

MEDIUM CVSS 6.5 2026-03-13
Scroll to top