Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 441-460 of 18002 records
Threat Entry Updated 2026-07-08

CVE-2026-12002 - Smash Balloon Social Photo Feed – Easy Social Feeds Plugin

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Smash Balloon Social Photo Feed – Easy Social Feeds Plugin

CVE-2026-12002

MEDIUM CVSS 4.7 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6854 - My Calendar – Accessible Event Manager Plugin

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN My Calendar – Accessible Event Manager

CVE-2026-6854

HIGH CVSS 7.5 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6818 - VikBooking Hotel Booking Engine & PMS Plugin

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN VikBooking Hotel Booking Engine & PMS

CVE-2026-6818

HIGH CVSS 7.2 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-3688 - WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Plugin

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.

PLUGIN WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

CVE-2026-3688

HIGH CVSS 8.1 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6230 - Tainacan Plugin

The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Tainacan

CVE-2026-6230

HIGH CVSS 7.5 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6742 - Advanced Iframe Plugin

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Advanced Iframe

CVE-2026-6742

MEDIUM CVSS 6.4 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14250 - TH Login Registration Theme

The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled 'role' parameter and validating it only against get_editable_roles() — which returns every defined editable site role, including 'editor' — before passing it to wp_insert_user(). This makes it possible for unauthenticated attackers, when public user registration is enabled, to create new accounts with the editor role.

THEME TH Login Registration

CVE-2026-14250

MEDIUM CVSS 6.3 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12936 - Recurio – Ultimate Subscription for WooCommerce Plugin

The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 1.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Recurio – Ultimate Subscription for WooCommerce

CVE-2026-12936

MEDIUM CVSS 4.9 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12378 - Appointment Booking Calendar Plugin and Scheduling Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.

PLUGIN Appointment Booking Calendar Plugin and Scheduling Plugin

CVE-2026-12378

HIGH CVSS 8.1 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-9700 - Eventer Plugin

The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Eventer

CVE-2026-9700

HIGH CVSS 7.5 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-9731 - Wp Js Detect Plugin

The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorrect nonce validation on the plugin_settings function. This makes it possible for unauthenticated attackers to update the plugin's notification text and CSS settings (wp_non_js_notification_text and wp_non_js_notification_css), injecting arbitrary content that is echoed unescaped on the frontend via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Js Detect

CVE-2026-9731

MEDIUM CVSS 4.3 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12153 - Wp Learn Manager Plugin

The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository on the vulnerable site.

PLUGIN Wp Learn Manager

CVE-2026-12153

CRITICAL CVSS 9.8 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14495 - Dologin Security Plugin

The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4.3. The vulnerability exists because `dologin\s::rrand()` seeds the Mersenne Twister with `mt_srand((double) microtime() * 1000000)` — discarding the integer-seconds component of `microtime()` and constraining the seed to a range of approximately 10^6 values (~20 bits of entropy) — after which every character of the 32-character magic-link token is drawn sequentially with `mt_rand()`, making the entire token a deterministic function of that seed. Because `Pswdless::try_login()` is registered on the unauthenticated…

PLUGIN Dologin Security

CVE-2026-14495

HIGH CVSS 8.8 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14489 - Whmcs Bridge Plugin

The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Whmcs Bridge

CVE-2026-14489

HIGH CVSS 8.8 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14500 - Bulk Order Update For Woocommerce Plugin

The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due to the bouw_fetch_csv_data() AJAX handler being registered on the wp_ajax_nopriv_ hook with no capability or nonce check, and passing the attacker-supplied csv_url POST parameter — filtered only by esc_url_raw() (which leaves absolute filesystem paths intact) and validate_file() (which only rejects '..' traversal patterns) — directly into fopen()/fgetcsv() and reflecting the first parsed line in the JSON response. This makes it possible for unauthenticated attackers to…

PLUGIN Bulk Order Update For Woocommerce

CVE-2026-14500

MEDIUM CVSS 5.3 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12097 - User Management Plugin

The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the plugin's export field configuration stored in the uiewp_export_field option, controlling which user fields such as password hashes are included in CSV exports and how columns are mapped during imports.

PLUGIN User Management

CVE-2026-12097

MEDIUM CVSS 5.3 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-11798 - Social Share, Social Login and Social Comments Plugin – Super Socializer

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and including, 7.14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Social Share, Social Login and Social Comments Plugin – Super Socializer

CVE-2026-11798

MEDIUM CVSS 6.1 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12041 - Chatra Live Chat + ChatBot + Cart Saver Plugin

The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Chatra Live Chat + ChatBot + Cart Saver

CVE-2026-12041

MEDIUM CVSS 4.4 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-10570 - Sympl Repeater For Acf And Elementor Plugin

The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping in the symp_arfe_replace_content() function, which uses str_replace() to substitute raw ACF field values (retrieved via get_field()) directly into Elementor-rendered HTML without any escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected…

PLUGIN Sympl Repeater For Acf And Elementor

CVE-2026-10570

MEDIUM CVSS 6.4 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-9842 - Backstage – Customizer Demo Access Plugin

The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to the plugin assigning the `manage_options` capability to the `backstage_customizer_user` demo role, which is more permissive than necessary for Customizer-only demo access. This makes it possible for unauthenticated attackers to navigate beyond the Customizer and update arbitrary WordPress options such as `default_role`, leading to privilege escalation.

PLUGIN Backstage – Customizer Demo Access

CVE-2026-9842

HIGH CVSS 7.5 2026-07-08
Scroll to top