Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,432
Critical1,287
High4,421
Medium12,480
Reset
Showing 4201-4220 of 18432 records
Threat Entry Updated 2026-06-17

CVE-2026-25370 - WP Compress Plugin

Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress: from n/a through

PLUGIN WP Compress

CVE-2026-25370

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25367 - CitiLights Plugin

Missing Authorization vulnerability in NooTheme CitiLights noo-citilights allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CitiLights: from n/a through < 3.7.2.

PLUGIN CitiLights

CVE-2026-25367

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25364 - Client Invoicing by Sprout Invoices Plugin

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through

PLUGIN Client Invoicing by Sprout Invoices

CVE-2026-25364

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25363 - FooGallery Plugin

Missing Authorization vulnerability in FooPlugins FooGallery foogallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FooGallery: from n/a through

PLUGIN FooGallery

CVE-2026-25363

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25343 - WP SMS Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS wp-sms allows DOM-Based XSS.This issue affects WP SMS: from n/a through

PLUGIN WP SMS

CVE-2026-25343

MEDIUM CVSS 5.9 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25337 - Coachify Plugin

Cross-Site Request Forgery (CSRF) vulnerability in wpcoachify Coachify coachify allows Cross Site Request Forgery.This issue affects Coachify: from n/a through

PLUGIN Coachify

CVE-2026-25337

MEDIUM CVSS 5.4 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25348 - Download Alt Text AI Plugin

Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Alt Text AI: from n/a through

PLUGIN Download Alt Text AI

CVE-2026-25348

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25338 - AI ChatBot with ChatGPT and Content Generator by AYS Plugin

Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through

PLUGIN AI ChatBot with ChatGPT and Content Generator by AYS

CVE-2026-25338

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25336 - Coachify Plugin

Missing Authorization vulnerability in wpcoachify Coachify coachify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coachify: from n/a through

PLUGIN Coachify

CVE-2026-25336

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25333 - Shopwell Plugin

Missing Authorization vulnerability in peregrinethemes Shopwell shopwell allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shopwell: from n/a through

PLUGIN Shopwell

CVE-2026-25333

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25335 - Secure Copy Content Protection and Content Locking Plugin

Missing Authorization vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Secure Copy Content Protection and Content Locking: from n/a through

PLUGIN Secure Copy Content Protection and Content Locking

CVE-2026-25335

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25326 - CMSMasters Content Composer Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through

PLUGIN CMSMasters Content Composer

CVE-2026-25326

HIGH CVSS 7.5 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25331 - WP Activity Log Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log wp-security-audit-log allows DOM-Based XSS.This issue affects WP Activity Log: from n/a through

PLUGIN WP Activity Log

CVE-2026-25331

MEDIUM CVSS 6.5 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25332 - Endless Posts Navigation Plugin

Missing Authorization vulnerability in Fahad Mahmood Endless Posts Navigation endless-posts-navigation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Endless Posts Navigation: from n/a through

PLUGIN Endless Posts Navigation

CVE-2026-25332

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25325 - rtMedia for WordPress, BuddyPress and bbPress Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Retrieve Embedded Sensitive Data.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through

PLUGIN rtMedia for WordPress, BuddyPress and bbPress

CVE-2026-25325

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25330 - PublishPress Authors Plugin

Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through

PLUGIN PublishPress Authors

CVE-2026-25330

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25329 - Quiz And Survey Master Plugin

Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through

PLUGIN Quiz And Survey Master

CVE-2026-25329

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25322 - PublishPress Revisions Plugin

Cross-Site Request Forgery (CSRF) vulnerability in PublishPress PublishPress Revisions revisionary allows Cross Site Request Forgery.This issue affects PublishPress Revisions: from n/a through

PLUGIN PublishPress Revisions

CVE-2026-25322

MEDIUM CVSS 5.4 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25324 - Quiz And Survey Master Plugin

Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through

PLUGIN Quiz And Survey Master

CVE-2026-25324

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25321 - SupportCandy Plugin

Missing Authorization vulnerability in PSM Plugins SupportCandy supportcandy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SupportCandy: from n/a through

PLUGIN SupportCandy

CVE-2026-25321

MEDIUM CVSS 5.3 2026-02-19
Scroll to top