Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-54824 - WordPress component
Unauthenticated Sensitive Data Exposure in Ads by WPQuads
CVE-2026-54824
CVE-2026-54833 - WordPress component
Unauthenticated Backdoor in Enable CORS
CVE-2026-54833
CVE-2026-54820 - WordPress component
Unauthenticated SQL Injection in JetBooking
CVE-2026-54820
CVE-2026-52701 - WordPress component
Unauthenticated Broken Access Control in User Registration
CVE-2026-52701
CVE-2026-24547 - WordPress component
Unauthenticated Broken Access Control in SiteGround Email Marketing
CVE-2026-24547
CVE-2026-57620 - Elementor Plugin
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8.
CVE-2026-57620
CVE-2026-1869 - Login Builder Plugin
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.
CVE-2026-1869
CVE-2026-10835 - Before 3 Plugin
The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal permissions, such as subscribers, to perform SQL injection attacks.
CVE-2026-10835
CVE-2026-10823 - Ymc Filter Plugin
The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts.
CVE-2026-10823
CVE-2026-8380 - Frontend File Manager Plugin
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin through 23.6's "Allow guest uploads" setting is enabled by an administrator, the same deletion primitive becomes reachable by unauthenticated users.
CVE-2026-8380
CVE-2026-13226 - And Marketing Automation Plugin
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up to, and including, 4.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Sales Manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The AJAX handler wp_ajax_groundhogg_get_contacts_table has its capability check commented…
CVE-2026-13226
CVE-2026-57700 - OMGF Pro Plugin
Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.
CVE-2026-57700
CVE-2026-57619 - Elementor Website Builder Plugin
Contributor Sensitive Data Exposure in Elementor Website Builder
CVE-2026-57619
CVE-2026-57429 - WordPress component
Contributor Broken Access Control in Slim SEO
CVE-2026-57429
CVE-2026-56053 - WordPress component
Subscriber PHP Object Injection in EventPrime
CVE-2026-56053
CVE-2026-56054 - WordPress component
Subscriber Arbitrary File Deletion in JS Help Desk
CVE-2026-56054
CVE-2026-56071 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Forminator
CVE-2026-56071
CVE-2026-56051 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in TablePress
CVE-2026-56051
CVE-2026-56049 - WordPress component
Contributor Remote Code Execution (RCE) in Post Snippets
CVE-2026-56049
CVE-2026-56042 - WordPress component
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce
CVE-2026-56042
