Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 641-660 of 18002 records
Threat Entry Updated 2026-07-01

CVE-2026-12408 - Slim SEO – A Fast & Automated SEO Plugin For WordPress

The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Content Disclosure in all versions up to, and including, 4.9.8 via the `/wp-json/slim-seo/meta-tags/ai` REST API endpoint. This is due to the endpoint's `permission_callback` performing only a top-level `edit_posts` capability check without verifying that the requesting user has read access to the specific post supplied via the `object.ID` parameter, allowing the `generate` function to pass the attacker-controlled post ID to `Data::get_post_content()`, which calls `get_post()` regardless of post status or ownership. This…

PLUGIN Slim SEO – A Fast & Automated SEO Plugin For WordPress

CVE-2026-12408

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-10096 - Qi Blocks Plugin

The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to modify the stored Qi Blocks styles of arbitrary posts, templates, or widgets they do not own — including site-wide surfaces via the reserved 'template' and 'widget' page_id values — enabling unauthorized frontend defacement, content hiding, and degradation of any page on the site.…

PLUGIN Qi Blocks

CVE-2026-10096

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11794 - Before 2 Plugin

The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public form field. This requires a specific, non-default multi-Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 configuration.

PLUGIN Before 2

CVE-2026-11794

HIGH CVSS 8.1 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11823 - Bookingpress Appointment Booking Pro Plugin

The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is interpolated verbatim into a SQL LIKE clause without use of $wpdb->prepare() or any parameterization. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Bookingpress Appointment Booking Pro

CVE-2026-11823

HIGH CVSS 7.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11568 - Product Configurator For Woocommerce Plugin

The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCommerce product data through a public AJAX action, allowing unauthenticated users to retrieve the data (title, price, weight, stock status, and configurator option pricing/SKUs) of private and draft, non-public products by supplying the product ID. WordPress post-visibility controls are bypassed.

PLUGIN Product Configurator For Woocommerce

CVE-2026-11568

HIGH CVSS 7.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-1239 - Contact Form Builder That Grows With You Plugin

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers to view form submissions, which could potentially contain sensitive information.

PLUGIN Contact Form Builder That Grows With You

CVE-2026-1239

HIGH CVSS 7.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11883 - Webauthn Provider For Two Factor Plugin

The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an attacker who already knows a user's password to bypass the two-factor authentication requirement by submitting a malformed request.

PLUGIN Webauthn Provider For Two Factor

CVE-2026-11883

HIGH CVSS 7.2 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11887 - Salon Booking System Plugin

The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings.

PLUGIN Salon Booking System

CVE-2026-11887

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11570 - User Submitted Posts Plugin

The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an admin-configured display template, leading to a Stored Cross-Site Scripting that can be triggered by unauthenticated users when a non-default display option is enabled.

PLUGIN User Submitted Posts

CVE-2026-11570

MEDIUM CVSS 4.2 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11880 - Fluent Forms Plugin

The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.

PLUGIN Fluent Forms

CVE-2026-11880

LOW CVSS 3.1 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-10750 - Royal Mcp Plugin

The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles, and create, modify, or delete content owned by other users.

PLUGIN Royal Mcp

CVE-2026-10750

HIGH CVSS 8.1 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11562 - Ws Form Lite Plugin

The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions, allowing authenticated users with subscriber-level access and above to modify the WS Form LITE WordPress plugin before 1.11.8's settings.

PLUGIN Ws Form Lite

CVE-2026-11562

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-9107 - Kali Forms — Contact Form & Drag-and-Drop Builder Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Kali Forms — Contact Form & Drag-and-Drop Builder

CVE-2026-9107

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-6070 - Wp Businessdirectory Plugin

The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The task=upload.remove endpoint is accessible without authentication via the plugin's frontend routing system. The _filename parameter is accepted with RAW filter (no sanitization), and the helper function makePathFile() only normalizes directory separator characters without stripping path traversal sequences (../). When combined with the _path_type=2 parameter, which sets the base directory to the plugin's site folder, an…

PLUGIN Wp Businessdirectory

CVE-2026-6070

CRITICAL CVSS 9.1 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-7517 - Custom Payment Gateways For Woocommerce Plugin

The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is exploitable by unauthenticated guest users submitting a crafted checkout POST request, requiring no custom input fields to be configured in the plugin.

PLUGIN Custom Payment Gateways For Woocommerce

CVE-2026-7517

HIGH CVSS 7.2 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-2387 - Event Organiser Plugin

The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.12.9. This is due to the 'eo_events' shortcode accepting attacker-controlled 'no_events' content and rendering it in event list templates without output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Event Organiser

CVE-2026-2387

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-13468 - Charts Manager With Built In Ai Generator Plugin

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to access and export the contents of any visualizer chart on the site — including charts in draft, private, pending, future, or trash status — as CSV, Excel, or HTML via the /wp-json/visualizer/v1/action/{chart}/{type}/ REST endpoint. This bypass is…

PLUGIN Charts Manager With Built In Ai Generator

CVE-2026-13468

HIGH CVSS 7.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12923 - Youtube Showcase Plugin

The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient validation of the 'path' parameter in the emd_delete_file() AJAX handler in includes/common-functions.php. The user-supplied value is passed through sanitize_text_field(), has its trailing '_PLUGIN_DIR' substring stripped, and is then invoked as a PHP function name with no arguments via `$sess_name()`. The handler is gated only by a nonce — no current_user_can() check is present — and the nonce is emitted on any front-end page that renders a…

PLUGIN Youtube Showcase

CVE-2026-12923

HIGH CVSS 7.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-13731 - WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Plugin

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The AJAX nonce required to authenticate the save request is publicly emitted on every frontend page via wp_localize_script, making it freely obtainable by any anonymous…

PLUGIN WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

CVE-2026-13731

HIGH CVSS 7.2 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-13443 - Elearning And Online Course Solution Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in all versions up to, and including, 3.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elearning And Online Course Solution

CVE-2026-13443

MEDIUM CVSS 6.4 2026-07-01
Scroll to top