Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 661-680 of 18002 records
Threat Entry Updated 2026-07-01

CVE-2026-13246 - Donation Plugin And Fundraising Platform

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_id' (and other) shortcode attributes of the 'givewp_campaign_comments' shortcode in versions up to, and including, 4.16.0. This is due to insufficient input sanitization and output escaping on user supplied attributes in CampaignCommentsShortcode::parseAttributes() and BlockRenderController::render(), where the blockId value is interpolated directly into a single-quoted HTML attribute without esc_attr(). This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever…

PLUGIN Donation Plugin And Fundraising Platform

CVE-2026-13246

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-13015 - Wp Google Places Review Slider Plugin

The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is URL-decoded, stripslashes()'d, and echoed directly into an HTML value attribute with no esc_attr() call when the supplied place is not already a stored key in the wprev_google_crawls option. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can…

PLUGIN Wp Google Places Review Slider

CVE-2026-13015

MEDIUM CVSS 6.1 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12110 - Taskbuilder – Project Management & Task Management Tool With Kanban Board Plugin

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'task_search' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The wppm_get_task_list AJAX handler performs no…

PLUGIN Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-12110

MEDIUM CVSS 6.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12135 - Fv Flowplayer Video Player Plugin

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Fv Flowplayer Video Player

CVE-2026-12135

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12127 - WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More Plugin

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name through smart-tag expansion with context `'notification'` instead of `'notification-reply-to'`, which bypasses email-address validation while `wpforms_sanitize_textarea_field()` intentionally preserves CR/LF characters that are never stripped before the display name is concatenated into the raw `Reply-To:` mail header string. This makes it possible for unauthenticated attackers…

PLUGIN WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

CVE-2026-12127

MEDIUM CVSS 5.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12904 - Kadence Blocks Plugin

The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.7.7. This is due to a mismatch between the object used for authorization and the object actually accessed in the Optimize_Rest_Controller's create_item(), get_item(), delete_item(), and bulk_delete_items() endpoints — authorization is checked via current_user_can('edit_post'/'delete_post', $post_id) against the user-supplied post_id, while the storage layer keys analysis records on sha256($post_path) from a separately supplied, attacker-controlled post_path parameter, with no enforcement that post_path corresponds to post_id. This makes…

PLUGIN Kadence Blocks

CVE-2026-12904

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12902 - Kadence Blocks — Page Builder Toolkit for Gutenberg Editor Plugin

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to create arbitrary Media Library attachments by downloading remote images to the site's uploads directory via wp_upload_bits() and wp_insert_attachment(), bypassing the upload_files capability boundary.

PLUGIN Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

CVE-2026-12902

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12133 - JoomSport – for Sports: Team & League, Football, Hockey & more Plugin

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability check in the joomsport_season_groupdel() AJAX handler, which only verifies a nonce before executing a DELETE query on attacker-supplied group IDs. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary JoomSport group records.

PLUGIN JoomSport – for Sports: Team & League, Football, Hockey & more

CVE-2026-12133

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12113 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email addresses, phone numbers, appointment comments, and other booking personally identifiable information.

PLUGIN Appointment Booking Calendar

CVE-2026-12113

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12090 - Taskbuilder – Project Management & Task Management Tool With Kanban Board Plugin

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'wppm_proj_filter' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. No nonce verification is performed on…

PLUGIN Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-12090

MEDIUM CVSS 6.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11988 - LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.9.1 via the 'userId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to view the course enrollment progress and completion data belonging to any instructor or administrator account on the site. This IDOR does not apply when the target user is a regular subscriber, as the guard…

PLUGIN LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

CVE-2026-11988

MEDIUM CVSS 6.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11380 - Jetwidgets For Elementor Plugin

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to insufficient output escaping and missing server-side validation of the Animated Box widget's animation_effect setting before it is rendered inside an HTML class attribute. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Jetwidgets For Elementor

CVE-2026-11380

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11981 - GiveWP – Donation Plugin and Fundraising Platform

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 This is due to missing nonce validation on the give_set_notification_status_handler() function. This makes it possible for unauthenticated attackers to disable donation email notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN GiveWP – Donation Plugin and Fundraising Platform

CVE-2026-11981

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-10513 - Webmention Plugin

The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 via parser-derived 'avatar' and 'url' author metadata. This is due to insufficient input sanitization and output escaping on user-supplied MF2 author properties processed by the unauthenticated webmention REST endpoint and rendered directly into HTML 'value' attributes by the edit-comment-form template without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a privileged user (moderator or administrator) opens the affected comment…

PLUGIN Webmention

CVE-2026-10513

HIGH CVSS 7.2 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-9711 - Eventon Wordpress Virtual Event Calendar Plugin

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter and lack of preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database, granted the "Enable additional search queries" setting is enabled and at least one published event exists.

PLUGIN Eventon Wordpress Virtual Event Calendar

CVE-2026-9711

CRITICAL CVSS 9.8 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-8141 - Ajax Load More Filters Plugin

The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ajax Load More Filters

CVE-2026-8141

HIGH CVSS 7.2 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-9576 - Fluent Booking Plugin

The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do not own.

PLUGIN Fluent Booking

CVE-2026-9576

MEDIUM CVSS 4.9 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-11589 - Wp Support Plus Responsive Ticket System Plugin

The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, allowing unauthenticated users to upload files containing malicious JavaScript (such as HTML or SVG) to a publicly accessible location, leading to Stored Cross-Site Scripting attacks against site users and administrators.

PLUGIN Wp Support Plus Responsive Ticket System

CVE-2026-11589

HIGH CVSS 8.8 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-12240 - Export User Data Plugin

The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Successful exploitation requires an administrator to trigger a user data export while a subscriber-level (or higher) user has stored a crafted serialized XLSXWriter…

PLUGIN Export User Data

CVE-2026-12240

HIGH CVSS 8.0 2026-06-30
Scroll to top