Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3541-3560 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-3459 - Drag And Drop Multiple File Upload Contact Form 7 Plugin

The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This can be exploited if the form includes a multiple file upload field with ‘*’ as the accepted file type.

PLUGIN Drag And Drop Multiple File Upload Contact Form 7

CVE-2026-3459

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-1720 - Create Stunning Popups And Optins For Lead Generation Plugin

The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the 'install_and_active_plugin' function in all versions up to, and including, 1.4.24. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins.

PLUGIN Create Stunning Popups And Optins For Lead Generation

CVE-2026-1720

HIGH CVSS 8.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-2599 - Contact Form Entries Plugin

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme…

PLUGIN Contact Form Entries

CVE-2026-2599

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-2893 - Page And Post Clone Plugin

The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_clone() function in all versions up to, and including, 6.3. This is due to insufficient escaping on the user-supplied meta_key value and insufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The injection is second-order: the malicious payload is stored as…

PLUGIN Page And Post Clone

CVE-2026-2893

MEDIUM CVSS 6.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-1321 - Restrict Content Plugin

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` function accepting any membership level ID via the `rcp_level` POST parameter without validating that the level is active or that payment is required. Combined with the `add_user_role()` method which assigns the WordPress role configured on the membership level without status checks, this makes it possible for unauthenticated attackers to register with any membership level, including inactive levels that grant privileged WordPress roles…

PLUGIN Restrict Content

CVE-2026-1321

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-3072 - Media Library Assistant Plugin

The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions up to, and including, 3.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify taxonomy terms on arbitrary attachments.

PLUGIN Media Library Assistant

CVE-2026-3072

MEDIUM CVSS 4.3 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-2418 - Login With Salesforce Plugin

The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

PLUGIN Login With Salesforce

CVE-2026-2418

CRITICAL CVSS 9.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28134 - JetEngine Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue affects JetEngine: from n/a through

PLUGIN JetEngine

CVE-2026-28134

HIGH CVSS 8.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28133 - Filr Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Filr: from n/a through

PLUGIN Filr

CVE-2026-28133

HIGH CVSS 8.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28135 - Royal Elementor Addons Plugin

Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Royal Elementor Addons: from n/a through

PLUGIN Royal Elementor Addons

CVE-2026-28135

HIGH CVSS 8.2 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28137 - MediCenter - Health Medical Clinic Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Reflected XSS.This issue affects MediCenter - Health Medical Clinic: from n/a through

PLUGIN MediCenter - Health Medical Clinic

CVE-2026-28137

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28129 - Little Birdies Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Little Birdies little-birdies allows PHP Local File Inclusion.This issue affects Little Birdies: from n/a through

PLUGIN Little Birdies

CVE-2026-28129

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28128 - Verse Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Verse verse allows PHP Local File Inclusion.This issue affects Verse: from n/a through

PLUGIN Verse

CVE-2026-28128

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28125 - Midi Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Midi midi allows PHP Local File Inclusion.This issue affects Midi: from n/a through

PLUGIN Midi

CVE-2026-28125

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28124 - Notarius Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Notarius notarius allows PHP Local File Inclusion.This issue affects Notarius: from n/a through

PLUGIN Notarius

CVE-2026-28124

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28123 - Veil Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Veil veil allows PHP Local File Inclusion.This issue affects Veil: from n/a through

PLUGIN Veil

CVE-2026-28123

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28130 - UDesign Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign u-design allows Reflected XSS.This issue affects UDesign: from n/a through

PLUGIN UDesign

CVE-2026-28130

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28127 - Lawyer Directory Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Lawyer Directory lawyer-directory allows Reflected XSS.This issue affects Lawyer Directory: from n/a through

PLUGIN Lawyer Directory

CVE-2026-28127

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28126 - RH Frontend Publishing Pro Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam RH Frontend Publishing Pro rh-frontend allows Reflected XSS.This issue affects RH Frontend Publishing Pro: from n/a through < 4.3.4.

PLUGIN RH Frontend Publishing Pro

CVE-2026-28126

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-28115 - WP Attractive Donations System - Easy Stripe & Paypal donations Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Blind SQL Injection.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from n/a through

PLUGIN WP Attractive Donations System - Easy Stripe & Paypal donations

CVE-2026-28115

CRITICAL CVSS 9.3 2026-03-05
Scroll to top