Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 681-700 of 18002 records
Threat Entry Updated 2026-06-30

CVE-2026-11581 - Drag And Drop Builder Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store JavaScript that executes in an administrator's session. A missing capability check in the Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13's post-duplication action additionally lets the Contributor publish the malicious form so an administrator renders it.

PLUGIN Drag And Drop Builder

CVE-2026-11581

MEDIUM CVSS 5.9 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-8944 - Io Engagement Analytics Plugin

The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the Google Analytics settings page (ga.php). This makes it possible for unauthenticated attackers to update the plugin's stored Google Analytics tracking ID option (io-ga-id) via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Io Engagement Analytics

CVE-2026-8944

MEDIUM CVSS 4.3 2026-06-30
Threat Entry Updated 2026-07-01

CVE-2026-12560 - Editorial Rating – Product Review & Rating System Plugin

The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Link URL' Field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The WordPress unfiltered_html capability exemption does not apply here because the payload is stored in post meta (_wpas_er_options via update_post_meta) rather than in…

PLUGIN Editorial Rating – Product Review & Rating System

CVE-2026-12560

MEDIUM CVSS 4.4 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-12073 - Groups And Communities Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't contain this parameter, and not properly handling the error messages. This makes it possible for unauthenticated attackers to change email address of user account with ID=1 (usually an administrator), and leverage that to reset the user's password and gain access to their account.

PLUGIN Groups And Communities

CVE-2026-12073

CRITICAL CVSS 9.8 2026-06-30
Threat Entry Updated 2026-07-01

CVE-2026-12349 - Premium Addons For Kingcomposer Plugin

The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX handlers, both of which are exposed through wp_ajax_nopriv_* hooks and write directly to the octagon_custom_sidebar option via update_option(). This makes it possible for unauthenticated attackers to create arbitrary custom widget areas or delete existing custom sidebars, which can cause widgets assigned to those areas to silently lose their registration and stop…

PLUGIN Premium Addons For Kingcomposer

CVE-2026-12349

MEDIUM CVSS 5.3 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-11367 - Wordpress Image Editor Plugin

The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the move_image_on_server function. This makes it possible for authenticated attackers, with author-level access and above, to write files with attacker-controlled content to arbitrary locations on the server. The unsanitized 'layers[].id' parameter is concatenated into a filesystem path and passed to PHP's copy() function, allowing traversal sequences (e.g. '../../') to escape the intended upload directory and write attacker-supplied file contents to arbitrary paths accessible by the web server…

PLUGIN Wordpress Image Editor

CVE-2026-11367

MEDIUM CVSS 6.5 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-12114 - Team Showcase Supreme Plugin

The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Team Showcase Supreme

CVE-2026-12114

MEDIUM CVSS 4.4 2026-06-30
Scroll to top