Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 921-940 of 18002 records
Threat Entry Updated 2026-06-25

CVE-2026-8614 - Assistio Plugin

The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin_delete_assistio_settings() function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's options including the critical 'assistiobot_oauth_settings' option, which disrupts the plugin's integration with the Assistio bot service.

PLUGIN Assistio

CVE-2026-8614

MEDIUM CVSS 4.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-6292 - Mp Customize Login Page Plugin

The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This is due to a completely broken nonce validation in the enter_mpclp_login_options() function, which contains an inverted check (if wp_verify_nonce(...) { return false; }) and is missing the required action parameter for wp_verify_nonce(). As a result, the nonce check is effectively dead code: it never blocks malicious requests because a CSRF-supplied empty/invalid nonce always returns false, satisfying the inverted condition to continue execution. Furthermore, the settings-update handler…

PLUGIN Mp Customize Login Page

CVE-2026-6292

MEDIUM CVSS 4.3 2026-06-24
Threat Entry Updated 2026-06-29

CVE-2026-12417 - SignUp & SignIn Plugin

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore accessible to unauthenticated users — performing no nonce verification, no capability check, and only a loose equality check between an attacker-supplied `reset_activation_code` POST parameter and the target user's `forgot_email` user meta value; when a user has never initiated a password reset, `get_user_meta()` returns an empty string that trivially…

PLUGIN SignUp & SignIn

CVE-2026-12417

CRITICAL CVSS 9.8 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-12416 - Invoice Generator Plugin

The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a loose equality comparison between the supplied `reset_activation_code` POST parameter and the target user's stored `forgot_email` user meta — a check that trivially evaluates to true (`'' == ''`) for any user who has never initiated a forgot-password request, which applies to administrators under…

PLUGIN Invoice Generator

CVE-2026-12416

CRITICAL CVSS 9.8 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-12100 - Url Preview Plugin

The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the 'url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Url Preview

CVE-2026-12100

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-12095 - Kargo Takip Plugin

The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The script echoes internal API response data (specifically the value of any 'auth' key in a JSON response body) verbatim back to the attacker's browser, enabling direct exfiltration of responses from internal services such as…

PLUGIN Kargo Takip

CVE-2026-12095

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-29

CVE-2026-11370 - Wp Meta Seo Plugin

The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The HTTP response status from outbound requests is reflected back in the AJAX JSON response as status_code, providing an enumeration oracle usable for probing internal hosts and cloud metadata…

PLUGIN Wp Meta Seo

CVE-2026-11370

MEDIUM CVSS 6.4 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-12094 - Advanced Contact Form 7 – Compact DB Plugin

The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_user() function in versions up to, and including, 1.0.0. The handler is registered against both `wp_ajax_cf7cdb_delete` and `wp_ajax_nopriv_cf7cdb_delete`, and it performs no nonce verification, no capability check, and no ownership check before invoking `$wpdb->delete()` against the `wp_cf7cdb_data` table with an attacker-supplied integer ID. This makes it possible for unauthenticated attackers to delete arbitrary contact form submission entries stored by the plugin by iterating sequential…

PLUGIN Advanced Contact Form 7 – Compact DB

CVE-2026-12094

MEDIUM CVSS 5.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-11997 - Bulk Seo Image Plugin

The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1. This is due to missing or incorrect nonce validation on the plugin's settings page handler BulkSeoImage(), which dispatches to launchbulk() / BulkSeoImageGo() whenever the request contains $_POST['bulkseoimage']. No wp_nonce_field() is emitted in the form and no check_admin_referer()/wp_verify_nonce() is performed before bulk-overwriting the _wp_attachment_image_alt post meta for every image attached to every published post and/or page. This makes it possible for unauthenticated attackers to bulk-overwrite image ALT-text metadata across the site…

PLUGIN Bulk Seo Image

CVE-2026-11997

MEDIUM CVSS 4.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10753 - Site Kit By Google Plugin

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing access (such as Editors) to modify a site-wide Site Kit by Google WordPress plugin before 1.176.0 setting that should only be modifiable by administrators.

PLUGIN Site Kit By Google

CVE-2026-10753

LOW CVSS 2.7 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10735 - Multiple Shapedsmart Post Show Pro Plugin

Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

PLUGIN Multiple Shapedsmart Post Show Pro

CVE-2026-10735

HIGH CVSS 7.5 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10749 - Post Duplicator Plugin

The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, storing attacker-supplied serialized values without the WordPress meta API's double-serialization protection, allowing users with Contributor-level access and above to inject a PHP Object.

PLUGIN Post Duplicator

CVE-2026-10749

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10092 - Cincopa Video And Media Plug In Plugin

The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortcode in Post Comments in all versions up to, and including, 1.163 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation is possible because the plugin processes the [cincopa] shortcode via a comment_text filter hook, allowing unauthenticated visitors who can post comments to supply a malicious shortcode argument that…

PLUGIN Cincopa Video And Media Plug In

CVE-2026-10092

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10091 - Email Javascript Cloak Plugin

The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Email Javascript Cloak

CVE-2026-10091

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10531 - Before 2 Plugin

The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2026-10531

MEDIUM CVSS 5.4 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10552 - Blue Captcha Plugin

The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or incorrect nonce validation on the main admin panel (blcap_main_page) and on the Hall of Shame and Log subpages, which accept a 'blcap_action' / 'action' parameter from $_REQUEST and perform destructive operations (plugin uninstall via blcap_uninstall(), log deletion via blcap_delete_logs(), Hall of Shame deletion via blcap_delete_ip_db(), and adding IPs to the banned list via update_option('blcap_settings')) with no wp_verify_nonce(), check_admin_referer(), or check_ajax_referer() calls anywhere in the codebase.…

PLUGIN Blue Captcha

CVE-2026-10552

MEDIUM CVSS 4.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-3652 - Arforms Plugin

The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX action in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator views the "Partial Filled Form Entries" page in the ARForms dashboard.

PLUGIN Arforms

CVE-2026-3652

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-11614 - Xpro Addons — 140+ Widgets for Elementor Plugin

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attributes' parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Xpro Addons — 140+ Widgets for Elementor

CVE-2026-11614

MEDIUM CVSS 6.4 2026-06-24
Threat Entry Updated 2026-06-29

CVE-2026-4610 - ProfileGrid – User Profiles, Groups and Communities Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 5.9.8.5.

PLUGIN ProfileGrid – User Profiles, Groups and Communities

CVE-2026-4610

MEDIUM CVSS 6.4 2026-06-23
Threat Entry Updated 2026-06-23

CVE-2026-8379 - Frontend File Manager Plugin

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers.

PLUGIN Frontend File Manager Plugin

CVE-2026-8379

HIGH CVSS 7.5 2026-06-23
Scroll to top