Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,541
Critical1,292
High4,446
Medium12,544
Reset
Showing 4921-4940 of 18541 records
Threat Entry Updated 2026-01-26

CVE-2025-15522 - Uncanny Automator Plugin

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automator_discord_user_mapping shortcode in all versions up to, and including, 6.10.0.2 due to insufficient input sanitization and output escaping on the verified_message parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user with a verified Discord account accesses the injected page.

PLUGIN Uncanny Automator

CVE-2025-15522

MEDIUM CVSS 6.4 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24390 - Elementor Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QantumThemes Kentha Elementor Widgets kentha-elementor allows PHP Local File Inclusion.This issue affects Kentha Elementor Widgets: from n/a through < 3.1.

PLUGIN Elementor

CVE-2026-24390

HIGH CVSS 7.5 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24389 - Gallery PhotoBlocks Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Gallery PhotoBlocks photoblocks-grid-gallery allows DOM-Based XSS.This issue affects Gallery PhotoBlocks: from n/a through

PLUGIN Gallery PhotoBlocks

CVE-2026-24389

MEDIUM CVSS 6.5 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24383 - B Slider Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Slider b-slider allows DOM-Based XSS.This issue affects B Slider: from n/a through

PLUGIN B Slider

CVE-2026-24383

MEDIUM CVSS 6.5 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24384 - Merge + Minify + Refresh Plugin

Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.This issue affects Merge + Minify + Refresh: from n/a through

PLUGIN Merge + Minify + Refresh

CVE-2026-24384

MEDIUM CVSS 5.4 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24381 - PhotoMe Plugin

Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods PhotoMe photome allows Server Side Request Forgery.This issue affects PhotoMe: from n/a through < 5.7.2.

PLUGIN PhotoMe

CVE-2026-24381

MEDIUM CVSS 5.4 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24388 - WPMasterToolKit Plugin

Missing Authorization vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPMasterToolKit: from n/a through

PLUGIN WPMasterToolKit

CVE-2026-24388

MEDIUM CVSS 4.3 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24387 - WP Quick Post Duplicator Plugin

Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator wp-quick-post-duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Quick Post Duplicator: from n/a through

PLUGIN WP Quick Post Duplicator

CVE-2026-24387

MEDIUM CVSS 4.3 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24386 - Element Invader – Template Kits for Elementor Plugin

Missing Authorization vulnerability in Element Invader Element Invader – Template Kits for Elementor elementinvader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Element Invader – Template Kits for Elementor: from n/a through

PLUGIN Element Invader – Template Kits for Elementor

CVE-2026-24386

MEDIUM CVSS 4.3 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24371 - BA Book Everything Plugin

Missing Authorization vulnerability in bookingalgorithms BA Book Everything ba-book-everything allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BA Book Everything: from n/a through

PLUGIN BA Book Everything

CVE-2026-24371

CRITICAL CVSS 9.8 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24379 - WP Job Portal Plugin

Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through

PLUGIN WP Job Portal

CVE-2026-24379

CRITICAL CVSS 9.1 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24380 - EventPrime Plugin

Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through

PLUGIN EventPrime

CVE-2026-24380

HIGH CVSS 8.8 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24368 - The Grid Plugin

Missing Authorization vulnerability in Theme-one The Grid the-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Grid: from n/a through < 2.8.0.

PLUGIN The Grid

CVE-2026-24368

HIGH CVSS 8.8 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24367 - Traveler Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through < 3.2.8.

PLUGIN Traveler

CVE-2026-24367

HIGH CVSS 8.8 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24377 - Nexter Blocks Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Retrieve Embedded Sensitive Data.This issue affects Nexter Blocks: from n/a through

PLUGIN Nexter Blocks

CVE-2026-24377

HIGH CVSS 7.5 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24374 - RegistrationMagic Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Cross Site Request Forgery.This issue affects RegistrationMagic: from n/a through

PLUGIN RegistrationMagic

CVE-2026-24374

MEDIUM CVSS 5.4 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24366 - WooCommerce Plugin

Missing Authorization vulnerability in YITHEMES YITH WooCommerce Request A Quote yith-woocommerce-request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Request A Quote: from n/a through

PLUGIN WooCommerce

CVE-2026-24366

MEDIUM CVSS 5.3 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24358 - Quiz And Survey Master Plugin

Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through

PLUGIN Quiz And Survey Master

CVE-2026-24358

HIGH CVSS 8.8 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-24356 - GetGenie Plugin

Missing Authorization vulnerability in Roxnor GetGenie getgenie allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetGenie: from n/a through

PLUGIN GetGenie

CVE-2026-24356

HIGH CVSS 8.8 2026-01-22
Scroll to top