Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14,955
Critical920
High3,037
Medium10,799
Reset
Showing 521-540 of 14955 records
Threat Entry Updated 2026-03-04

CVE-2026-2363 - WP-Members Membership Plugin

The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the [wpmem_user_membership_posts] shortcode in all versions up to, and including, 3.5.5.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN WP-Members Membership Plugin

CVE-2026-2363

MEDIUM CVSS 6.5 2026-03-04
Threat Entry Updated 2026-03-04

CVE-2026-2732 - Enable Media Replace Plugin

The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-level access and above, to replace any attachment with a removed background attachment.

PLUGIN Enable Media Replace

CVE-2026-2732

MEDIUM CVSS 5.4 2026-03-04
Threat Entry Updated 2026-04-15

CVE-2026-2025 - Before 1 Plugin

The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog

PLUGIN Before 1

CVE-2026-2025

HIGH CVSS 7.5 2026-03-04
Threat Entry Updated 2026-03-04

CVE-2026-1980 - Wpbookit Plugin

The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails, phone numbers, dates of birth, and gender.

PLUGIN Wpbookit

CVE-2026-1980

MEDIUM CVSS 5.3 2026-03-04
Threat Entry Updated 2026-03-04

CVE-2026-2292 - Morkva Ua Shipping Plugin

The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Morkva Ua Shipping

CVE-2026-2292

MEDIUM CVSS 4.4 2026-03-04
Threat Entry Updated 2026-03-04

CVE-2026-2289 - Taskbuilder – Project Management & Task Management Tool With Kanban Board Plugin

The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-2289

MEDIUM CVSS 4.4 2026-03-04
Threat Entry Updated 2026-03-04

CVE-2026-1945 - Wpbookit Plugin

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wpbookit

CVE-2026-1945

HIGH CVSS 7.2 2026-03-04
Threat Entry Updated 2026-03-04

CVE-2026-1273 - Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX Plugin

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.8 via the `/ultp/v3/starter_dummy_post/` and `/ultp/v3/starter_import_content/` REST API endpoints. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX

CVE-2026-1273

HIGH CVSS 7.2 2026-03-04
Threat Entry Updated 2026-03-04

CVE-2026-1651 - Email Subscribers Plugin

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' parameter in all versions up to, and including, 5.9.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Email Subscribers

CVE-2026-1651

MEDIUM CVSS 6.5 2026-03-04
Threat Entry Updated 2026-03-03

CVE-2026-2568 - Formidable And Ninja Forms Plugin

The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission data in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Formidable And Ninja Forms

CVE-2026-2568

HIGH CVSS 7.2 2026-03-03
Threat Entry Updated 2026-03-03

CVE-2026-1492 - User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Plugin

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.

PLUGIN User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-1492

CRITICAL CVSS 9.8 2026-03-03
Threat Entry Updated 2026-03-03

CVE-2026-2628 - All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login Plugin

The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.

PLUGIN All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login

CVE-2026-2628

CRITICAL CVSS 9.8 2026-03-03
Threat Entry Updated 2026-03-03

CVE-2026-2448 - Page Builder By Siteorigin Plugin

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate_template() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Page Builder By Siteorigin

CVE-2026-2448

HIGH CVSS 8.8 2026-03-03
Threat Entry Updated 2026-03-03

CVE-2026-2269 - Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Additionally, the plugin stores the contents of the remote files on the server, which can be leveraged to upload arbitrary files…

PLUGIN Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

CVE-2026-2269

HIGH CVSS 7.2 2026-03-03
Threat Entry Updated 2026-03-03

CVE-2026-1487 - Calendar Booking Plugin For Appointments And Events

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injection via the JSON Import in all versions up to, and including, 5.2.7 due to insufficient validation on the user-supplied JSON data. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary SQL queries on the database that can be used to extract information via time-based techniques, drop tables, or modify data.

PLUGIN Calendar Booking Plugin For Appointments And Events

CVE-2026-1487

MEDIUM CVSS 6.5 2026-03-03
Threat Entry Updated 2026-03-03

CVE-2026-1566 - Calendar Booking Plugin For Appointments And Events

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 5.2.7. This is due to the plugin allowing users with a LatePoint Agent role, who are creating new customers to set the 'wordpress_user_id' field. This makes it possible for authenticated attackers, with Agent-level access and above, to gain elevated privileges by linking a customer to the arbitrary user ID, including administrators, and then resetting the password.

PLUGIN Calendar Booking Plugin For Appointments And Events

CVE-2026-1566

HIGH CVSS 8.8 2026-03-03
Threat Entry Updated 2026-03-03

CVE-2026-1336 - Ai Chatbot With Chatgpt And Content Generator By Ays Plugin

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the store_data() and get_chatgpt_api_key() functions in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to view, modify or delete the plugin's ChatGPT API key. The vulnerability was partially fixed in version 2.7.5 and fully fixed in version 2.7.6

PLUGIN Ai Chatbot With Chatgpt And Content Generator By Ays

CVE-2026-1336

MEDIUM CVSS 5.3 2026-03-03
Threat Entry Updated 2026-03-03

CVE-2026-2583 - Blocksy Theme

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in all versions up to, and including, 2.1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Blocksy

CVE-2026-2583

MEDIUM CVSS 6.4 2026-03-02
Threat Entry Updated 2026-03-02

CVE-2026-3180 - Contest Gallery Plugin

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerability's ’cgLostPasswordEmail’ parameter was patched…

PLUGIN Contest Gallery

CVE-2026-3180

HIGH CVSS 7.5 2026-03-02
Threat Entry Updated 2026-03-02

CVE-2026-3132 - Master Addons Plugin

The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_Widget_Admin::render_preview'. This is due to missing capability check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute code on the server.

PLUGIN Master Addons

CVE-2026-3132

HIGH CVSS 8.8 2026-03-02
Scroll to top