Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 381-400 of 18002 records
Threat Entry Updated 2026-07-10

CVE-2026-15284 - King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder Plugin

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization in the add_to_submissions() function, which applies sanitize_text_field() (which preserves double-quote characters) before storing the value in post meta, combined with missing output escaping in the king_addons_submissions_custom_column_content() function, which concatenates the stored value into an HTML href attribute via admin_url() without wrapping the result in esc_url(). This makes it possible for authenticated attackers, with subscriber-level access and above, to…

PLUGIN King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

CVE-2026-15284

MEDIUM CVSS 6.4 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15286 - Kadence Blocks — Page Builder Toolkit for Gutenberg Editor Plugin

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check' function permission callback of the 'process_pattern' REST API endpoint. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and immediately publish posts of any type (including pages), bypassing the standard WordPress review workflow where contributors must submit posts for administrator approval.

PLUGIN Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

CVE-2026-15286

MEDIUM CVSS 4.3 2026-07-10
Threat Entry Updated 2026-07-14

CVE-2026-15282 - Instant Appointment Plugin

The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Instant Appointment

CVE-2026-15282

CRITICAL CVSS 9.8 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15283 - Wpvivid Backup For Mainwp Plugin

The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.9.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Wpvivid Backup For Mainwp

CVE-2026-15283

MEDIUM CVSS 4.4 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-5069 - Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin

The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with subscriber-level access and above, to submit cancellation requests for other users' subscriptions.

PLUGIN Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

CVE-2026-5069

MEDIUM CVSS 5.4 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-14894 - Super Forms – Drag & Drop Form Builder Plugin

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce…

PLUGIN Super Forms – Drag & Drop Form Builder

CVE-2026-14894

CRITICAL CVSS 9.8 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15070 - Salon Booking System – Free Version Plugin

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This is due to missing or incorrect nonce validation on the setCustomText function. This makes it possible for unauthenticated attackers to inject arbitrary PHP code into the web-accessible translate-constants.php file within the plugin directory, enabling remote code execution on the server via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. sanitize_text_field() is applied to…

PLUGIN Salon Booking System – Free Version

CVE-2026-15070

HIGH CVSS 8.8 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-13430 - Post Export Import With Media Plugin

The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure function. This is due to insufficient file extension validation caused by a trailing-dot filename bypass, where the extension allow-list check in ajax_import_media_start() uses pathinfo() on the raw ZIP entry name (e.g., 'shell.php.'), which returns an empty string for the extension, causing the allow-list guard to be skipped and the file to be extracted to a temporary location, after which import_media_file_secure() copies it into the…

PLUGIN Post Export Import With Media

CVE-2026-13430

HIGH CVSS 7.2 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-11818 - WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System Plugin

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to list, create, update, delete, clone, and bulk-delete notification flow workflows that are intended to be managed only by administrators. The only protection on these endpoints is a wp_rest nonce check, which…

PLUGIN WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

CVE-2026-11818

MEDIUM CVSS 5.4 2026-07-10
Threat Entry Updated 2026-07-14

CVE-2026-11392 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Hotel Booking

CVE-2026-11392

MEDIUM CVSS 6.1 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-12598 - Loginpress Pro Plugin

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me endpoint and using it directly with get_user_by('email', $profile['email']) to identify and log in an existing WordPress account, without confirming that the Spotify user actually owns the email address (Spotify documents that the profile email is unverified) and without requiring the user to prove ownership of the matching WordPress account. This…

PLUGIN Loginpress Pro

CVE-2026-12598

HIGH CVSS 8.1 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-12597 - Loginpress Pro Plugin

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array returned by GitHub's /user/emails endpoint as an account-binding identifier without verifying that the email carries a verified === true status. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by adding an unverified email address matching a local account to their GitHub…

PLUGIN Loginpress Pro

CVE-2026-12597

HIGH CVSS 8.1 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-12595 - Loginpress Pro Plugin

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field returned by Discord's /users/@me endpoint without ever checking that the profile's verified flag is true, then directly maps that email to a local WordPress account via get_user_by('email', $profile['email']) and issues an authenticated session cookie via wp_set_auth_cookie(). This makes it possible for unauthenticated attackers to take over any existing WordPress account — including…

PLUGIN Loginpress Pro

CVE-2026-12595

HIGH CVSS 8.1 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-13492 - UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function (which falls through to sanitize_text_field() for fields of type 'file', leaving directory-traversal sequences intact) combined with the UsersWP_Forms::upload_file_remove() AJAX handler building the deletion target from the uploads basedir concatenated with the attacker-controlled metadata value without any realpath canonicalization or uploads-directory boundary check before calling unlink(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…

PLUGIN UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

CVE-2026-13492

HIGH CVSS 8.8 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-9253 - WordPress component

The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versions up to, and including, 10.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

UNKNOWN WordPress component

CVE-2026-9253

HIGH CVSS 7.2 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-9028 - Corvuspay Woocommerce Integration Plugin

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to cancel any WooCommerce order placed via the CorvusPay payment method by supplying an arbitrary order number to the /wp-json/corvuspay/cancel/ REST endpoint.

PLUGIN Corvuspay Woocommerce Integration

CVE-2026-9028

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-9027 - Corvuspay Woocommerce Integration Plugin

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. The `corvuspay_success_handler` function registers the REST endpoint `POST /wp-json/corvuspay/success/` with `'permission_callback' => '__return_true'`, and while it calls `$this->client->validate->signature()` and stores the boolean result in `$res`, the result is never evaluated in a conditional — it is only written to the debug log — causing execution to unconditionally reach `$order->payment_complete()` regardless of whether the cryptographic signature is valid. This makes it possible for unauthenticated…

PLUGIN Corvuspay Woocommerce Integration

CVE-2026-9027

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-9240 - Colissimo Shipping Methods For Woocommerce Plugin

The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateShippingMethod() function (registered to the wp_ajax_lpc_order_affect AJAX action) in versions up to, and including, 2.9.0. This is due to the handler performing no current_user_can() capability check and no nonce verification before reading an attacker-supplied order_id and modifying that order's shipping method, pickup-point meta, and shipping address. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create or modify the…

PLUGIN Colissimo Shipping Methods For Woocommerce

CVE-2026-9240

MEDIUM CVSS 4.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-9237 - Hr Management Plugin

The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete, archive, unarchive, and duplicate arbitrary job listings — along with their associated stages, meta, addresses, and applications — by supplying an arbitrary integer job_id. The nonce verified by Dispatcher::dispatch() is exposed to…

PLUGIN Hr Management

CVE-2026-9237

MEDIUM CVSS 4.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-9235 - For Woocommerce Plugin

The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce verification on the create_label() and delete_label() functions in versions up to, and including, 2.2.3. These functions are wired to the wp_ajax_dhlpwc_label_create and wp_ajax_dhlpwc_label_delete hooks and act on an attacker-supplied post_id (WooCommerce order ID). This makes it possible for authenticated attackers, with Subscriber-level access and above, to create or delete DHL shipping labels associated with any WooCommerce order on the site.

PLUGIN For Woocommerce

CVE-2026-9235

MEDIUM CVSS 4.3 2026-07-09
Scroll to top