sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total20,019
Critical1,519
High5,010
Medium13,208
Reset
Showing 21-40 of 20019 records
Threat Entry Updated 2026-09-04

WPFunnels - Security Vulnerability (CVE-2026-79631)

The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order details and opt-in form submissions when logging is enabled.

PLUGIN WPFunnels

CVE-2026-79631

MEDIUM CVSS 5.3 2026-09-04
Threat Entry Updated 2026-09-04

WPFunnels - Security Vulnerability (CVE-2026-79630)

The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any purchasable product at a discount intended for a different one, with the reduced price carried through to the total of the order they place.

PLUGIN WPFunnels

CVE-2026-79630

MEDIUM CVSS 5.3 2026-09-04
Threat Entry Updated 2026-09-04

ACPT - Security Vulnerability (CVE-2026-15354)

The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions.

PLUGIN ACPT

CVE-2026-15354

CRITICAL CVSS 9.8 2026-09-04
Threat Entry Updated 2026-09-04

Classified Listing - Security Vulnerability (CVE-2026-16281)

The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.

PLUGIN Classified Listing

CVE-2026-16281

HIGH CVSS 7.1 2026-09-04
Threat Entry Updated 2026-09-04

Content Views - Security Vulnerability (CVE-2026-17517)

The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attackers to obtain the title and content of non-public posts, such as draft, pending, private and scheduled posts, when a view has been configured to include them.

PLUGIN Content Views

CVE-2026-17517

MEDIUM CVSS 5.3 2026-09-04
Threat Entry Updated 2026-09-04

Divi Ajax Filter - Security Vulnerability (CVE-2026-11613)

The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. This vulnerability is only exploitable when the loop_templates parameter is set…

PLUGIN Divi Ajax Filter

CVE-2026-11613

CRITICAL CVSS 9.8 2026-09-04
Threat Entry Updated 2026-09-03

Learnpress - Security Vulnerability (CVE-2026-82023)

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.

PLUGIN Learnpress

CVE-2026-82023

MEDIUM CVSS 5.3 2026-09-03
Threat Entry Updated 2026-09-03

Learnpress - Security Vulnerability (CVE-2026-82024)

LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz question answer title fields. Attackers can store arbitrary JavaScript through the answer title parameter, which is rendered through an unescaped HTML sink to execute in the browsers of any user who views the affected quiz question, including students, other instructors, and administrators.

PLUGIN Learnpress

CVE-2026-82024

MEDIUM CVSS 5.1 2026-09-03
Threat Entry Updated 2026-09-03

SureForms - Security Vulnerability (CVE-2026-85308)

Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5.

PLUGIN SureForms

CVE-2026-85308

MEDIUM CVSS 5.3 2026-09-03
Threat Entry Updated 2026-09-04

MountDev AI MCP Connector for WordPress - Security Vulnerability (CVE-2026-85306)

Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5.

PLUGIN MountDev AI MCP Connector for WordPress

CVE-2026-85306

MEDIUM CVSS 6.5 2026-09-03
Threat Entry Updated 2026-09-03

Elementor - Security Vulnerability (CVE-2026-85302)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2.

PLUGIN Elementor

CVE-2026-85302

MEDIUM CVSS 6.5 2026-09-03
Threat Entry Updated 2026-09-03

Elementor - Security Vulnerability (CVE-2026-85304)

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17.

PLUGIN Elementor

CVE-2026-85304

MEDIUM CVSS 5.3 2026-09-03