Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 61-80 of 18002 records
Threat Entry Updated 2026-07-17

CVE-2026-11324 - WordPress component

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

UNKNOWN WordPress component

CVE-2026-11324

MEDIUM CVSS 6.1 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15160 - Ninja Forms Excel Export Plugin

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to write .xls/.xlsx files to arbitrary locations on the server, which can be used to stage further attacks.

PLUGIN Ninja Forms Excel Export

CVE-2026-15160

MEDIUM CVSS 4.3 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15159 - Ninja Forms Excel Export Plugin

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate any Ninja Forms form ID and download all stored submission data — including names, email addresses, phone numbers, physical addresses, and any other PII collected by site forms — as a downloadable XLSX file.

PLUGIN Ninja Forms Excel Export

CVE-2026-15159

MEDIUM CVSS 4.3 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-2594 - Smart Custom Fields Plugin

The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was partially patched in 5.0.7.

PLUGIN Smart Custom Fields

CVE-2026-2594

MEDIUM CVSS 6.4 2026-07-17
Threat Entry Updated 2026-07-21

CVE-2026-14956 - Bricksforge Plugin

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to the trusted form-field whitelist. This makes it possible for unauthenticated attackers to register a new administrator account by submitting a crafted request to a publicly accessible Bricksforge Pro Forms registration form. Successful exploitation requires that the site has a public Bricksforge Pro Forms element configured with the…

PLUGIN Bricksforge

CVE-2026-14956

CRITICAL CVSS 9.8 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-14782 - Ameliabooking Plugin

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with wpamelia-manager role, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ameliabooking

CVE-2026-14782

MEDIUM CVSS 4.9 2026-07-16
Threat Entry Updated 2026-07-17

CVE-2026-7543 - Breakdance Plugin

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Breakdance

CVE-2026-7543

HIGH CVSS 7.2 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15727 - Wp Bulk Delete Plugin

The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. wp_unslash() is applied to the raw POST body before parse_str() decomposes it, stripping WordPress…

PLUGIN Wp Bulk Delete

CVE-2026-15727

MEDIUM CVSS 4.9 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15651 - Wp Tripadvisor Review Slider Plugin

The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, 14.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Tripadvisor Review Slider

CVE-2026-15651

MEDIUM CVSS 4.9 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15610 - Chatbot Plugin

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger arbitrary re-embedding of stored RAG documents, modifying the rag_documents table and consuming the site owner's paid third-party AI API credits (OpenAI, Gemini, OpenRouter, or xAI).

PLUGIN Chatbot

CVE-2026-15610

MEDIUM CVSS 4.3 2026-07-16
Threat Entry Updated 2026-07-18

CVE-2026-15407 - Themify Builder Plugin

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite or delete the generated CSS stylesheet file of arbitrary posts, including private and draft posts owned by other users, and modify plugin-scoped font options. The required CSRF nonce (tf_nonce) is emitted on public front-end builder pages via wp_localize_script, making…

PLUGIN Themify Builder

CVE-2026-15407

MEDIUM CVSS 4.3 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15350 - The Cache Purger Plugin

The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently truncate the plugin's cache-purge audit log (wp-content/purge.log), destroying the entire cache-purge audit history. The tcp_log_purge nonce is rendered in the admin bar on frontend pages accessible to all authenticated users including subscribers, meaning any authenticated user possesses the…

PLUGIN The Cache Purger

CVE-2026-15350

MEDIUM CVSS 4.3 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15103 - One Click Upsell Plugin

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This is due to the `update_settings()` REST callback failing to validate the `group_id` path parameter against an allowlist of permitted option names before passing it directly to `get_option()` and `update_option()`, allowing the built-in `wp_user_roles` option — which satisfies the route's loose `[\w-]+` regex — to be targeted. This makes it possible for authenticated attackers with the `wpf_manage_funnels`…

PLUGIN One Click Upsell

CVE-2026-15103

HIGH CVSS 8.8 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15005 - Loco Translate Plugin

The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the 'template' parameter, which bypasses path validation and is passed directly to the include sink in execTemplate() via a forged request granted they can trick a site administrator into performing an action such as…

PLUGIN Loco Translate

CVE-2026-15005

HIGH CVSS 8.8 2026-07-16
Threat Entry Updated 2026-07-17

CVE-2026-15008 - Uncanny Automator Plugin

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires a Forminator form connected to an Uncanny Automator recipe configured for 'Everyone', allowing unauthenticated form submissions to supply…

PLUGIN Uncanny Automator

CVE-2026-15008

HIGH CVSS 8.1 2026-07-16
Threat Entry Updated 2026-07-18

CVE-2026-15022 - Elearning And Online Course Solution Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all versions up to, and including, 4.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The payload is stored at quiz-attempt time via…

PLUGIN Elearning And Online Course Solution

CVE-2026-15022

MEDIUM CVSS 6.5 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15099 - Delicious Recipes Plugin

The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This is due to insufficient input sanitization and output escaping in the wrap_direction_text() function, which interpolates the user-supplied href value from nested link nodes ($node['props']['href']) directly into an anchor tag via sprintf() at line 1627 without esc_url() or any URL scheme validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts (including javascript: URIs) in pages that will…

PLUGIN Delicious Recipes

CVE-2026-15099

MEDIUM CVSS 6.4 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15021 - Wpforo Forum Plugin

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The sanitize_text_field() function applied at input does not encode double quotes, allowing attribute breakout via a payload that escapes the href attribute context and injects event handler attributes.

PLUGIN Wpforo Forum

CVE-2026-15021

MEDIUM CVSS 6.4 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15106 - Chatbot Plugin

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to delete arbitrary chat session records from the wpbot_user and wpbot_conversation tables, including chat history and conversation logs, by supplying a crafted userid value.

PLUGIN Chatbot

CVE-2026-15106

MEDIUM CVSS 5.3 2026-07-16
Threat Entry Updated 2026-07-17

CVE-2026-15324 - Customize My Account For Woocommerce Plugin

The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter in all versions up to, and including, 4.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Customize My Account For Woocommerce

CVE-2026-15324

MEDIUM CVSS 4.4 2026-07-16
Scroll to top