Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,472
Critical1,289
High4,429
Medium12,503
Reset
Showing 4621-4640 of 18472 records
Threat Entry Updated 2026-06-17

CVE-2026-24982 - Spectra Plugin

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through

PLUGIN Spectra

CVE-2026-24982

MEDIUM CVSS 5.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24967 - Amelia Plugin

Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through

PLUGIN Amelia

CVE-2026-24967

MEDIUM CVSS 5.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24985 - WP Forms Signature Contract Add-On Plugin

Missing Authorization vulnerability in approveme WP Forms Signature Contract Add-On wp-forms-signature-contract-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Forms Signature Contract Add-On: from n/a through

PLUGIN WP Forms Signature Contract Add-On

CVE-2026-24985

MEDIUM CVSS 4.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24966 - Copyscape Premium Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Copyscape Copyscape Premium copyscape-premium allows Cross Site Request Forgery.This issue affects Copyscape Premium: from n/a through

PLUGIN Copyscape Premium

CVE-2026-24966

MEDIUM CVSS 4.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24954 - WpEvently Plugin

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through

PLUGIN WpEvently

CVE-2026-24954

HIGH CVSS 8.8 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24958 - JetElements For Elementor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows DOM-Based XSS.This issue affects JetElements For Elementor: from n/a through

PLUGIN JetElements For Elementor

CVE-2026-24958

MEDIUM CVSS 6.5 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24957 - Strong Testimonials Plugin

Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials: from n/a through

PLUGIN Strong Testimonials

CVE-2026-24957

MEDIUM CVSS 6.5 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24952 - Seriously Simple Podcasting Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Stored XSS.This issue affects Seriously Simple Podcasting: from n/a through

PLUGIN Seriously Simple Podcasting

CVE-2026-24952

MEDIUM CVSS 6.5 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24961 - Grand Blog Plugin

Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Server Side Request Forgery.This issue affects Grand Blog: from n/a through < 3.1.5.

PLUGIN Grand Blog

CVE-2026-24961

MEDIUM CVSS 5.4 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24965 - Contest Gallery Plugin

Missing Authorization vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contest Gallery: from n/a through

PLUGIN Contest Gallery

CVE-2026-24965

MEDIUM CVSS 4.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24962 - Sigmize Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Sigmize sigmize allows Cross Site Request Forgery.This issue affects Sigmize: from n/a through

PLUGIN Sigmize

CVE-2026-24962

MEDIUM CVSS 4.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24951 - myCred Plugin

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through

PLUGIN myCred

CVE-2026-24951

MEDIUM CVSS 4.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24938 - Better Search Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Better Search better-search allows Stored XSS.This issue affects Better Search: from n/a through

PLUGIN Better Search

CVE-2026-24938

MEDIUM CVSS 5.9 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24945 - Ultimate Addons for Contact Form 7 Theme

Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through

THEME Ultimate Addons for Contact Form 7

CVE-2026-24945

MEDIUM CVSS 5.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24947 - Elementor Plugin

Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through < 1.5.6.3.

PLUGIN Elementor

CVE-2026-24947

MEDIUM CVSS 4.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24942 - WpEvently Plugin

Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Forgery.This issue affects WpEvently: from n/a through

PLUGIN WpEvently

CVE-2026-24942

MEDIUM CVSS 4.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24940 - Travelfic Toolkit Plugin

Missing Authorization vulnerability in Themefic Travelfic Toolkit travelfic-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travelfic Toolkit: from n/a through

PLUGIN Travelfic Toolkit

CVE-2026-24940

MEDIUM CVSS 4.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24939 - Modula Image Gallery Plugin

Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modula Image Gallery: from n/a through

PLUGIN Modula Image Gallery

CVE-2026-24939

MEDIUM CVSS 4.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-1730 - Os Datahub Maps Plugin

The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::add_file_and_ext' function in all versions up to, and including, 1.8.3. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Os Datahub Maps

CVE-2026-1730

HIGH CVSS 8.8 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-1375 - Elearning And Online Course Solution Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up to, and including, 3.9.5. This is due to missing object-level authorization checks in the `course_list_bulk_action()`, `bulk_delete_course()`, and `update_course_status()` functions. This makes it possible for authenticated attackers, with Tutor Instructor-level access and above, to modify or delete arbitrary courses they do not own by manipulating course IDs in bulk action requests.

PLUGIN Elearning And Online Course Solution

CVE-2026-1375

HIGH CVSS 8.1 2026-02-03
Scroll to top