Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 1001-1020 of 18002 records
Threat Entry Updated 2026-06-18

CVE-2026-11358 - Themeisle Companion Plugin

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Themeisle Companion

CVE-2026-11358

MEDIUM CVSS 4.4 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-11357 - Kadence Blocks Plugin

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.5 via the editor_assets_variables. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the site's connected Kadence account license key, license owner email, api_key, api_email, and license domain from the browser console by inspecting window.kadence_blocks_params.proData. Exploitation requires only that an administrator has previously connected a valid Kadence license; the full credential bundle is then readable by any Contributor-level user…

PLUGIN Kadence Blocks

CVE-2026-11357

MEDIUM CVSS 4.3 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-10623 - Pressprimer Quiz Plugin

The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.0 via the 'rule_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with custom-level access and above, to modify or delete quiz rules belonging to other teachers, resulting in unauthorized tampering of another user's quiz structure.

PLUGIN Pressprimer Quiz

CVE-2026-10623

MEDIUM CVSS 4.3 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-10029 - Eventkoi Lite Plugin

The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.13.1 via the get_events. This makes it possible for unauthenticated attackers to extract sensitive data including virtual meeting URLs, physical location data, latitude/longitude coordinates, Google Maps links, and RSVP configuration belonging to draft, pending, and private events that are otherwise inaccessible via public URLs.

PLUGIN Eventkoi Lite

CVE-2026-10029

MEDIUM CVSS 5.3 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-12407 - Export Pdf Tool For Wordpress Plugin

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.32.26. This is due to the screen_action() function lacking a dedicated capability check and nonce verification — when invoked via the ?action=screen routing path the controller's index_action() nonce gate is bypassed entirely — while reading an attacker-controlled option name and value from $_POST['wp_screen_options'] and passing them directly to update_option() with no allowlist, relying solely on the page-level e2pdf_templates capability which the plugin's own Permissions UI allows administrators to…

PLUGIN Export Pdf Tool For Wordpress

CVE-2026-12407

HIGH CVSS 8.8 2026-06-18
Threat Entry Updated 2026-06-18

CVE-2026-10023 - Dokan Lite Plugin

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add_order_note, delete_order_note, add_shipping_tracking_info, grant_access_to_download, and revoke_access_to_download AJAX handlers due to missing ownership validation on a user-controlled order ID key. This makes it possible for authenticated attackers, with custom vendor-level access and above, to modify the status of arbitrary orders, add attacker-controlled notes to any order (including customer-facing notes that trigger WooCommerce notification emails to…

PLUGIN Dokan Lite

CVE-2026-10023

MEDIUM CVSS 4.3 2026-06-18
Threat Entry Updated 2026-06-17

CVE-2026-54812 - Motors Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection. This issue affects Motors: from n/a through 1.4.109.

PLUGIN Motors

CVE-2026-54812

CRITICAL CVSS 9.3 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54810 - Nexi XPay Plugin

Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Nexi XPay: from n/a through 8.3.1.

PLUGIN Nexi XPay

CVE-2026-54810

HIGH CVSS 7.5 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54819 - Listdom Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.

PLUGIN Listdom

CVE-2026-54819

CRITICAL CVSS 9.3 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54815 - Cargo Shipping Location for WooCommerce Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.

PLUGIN Cargo Shipping Location for WooCommerce

CVE-2026-54815

CRITICAL CVSS 9.3 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54818 - Slimstat Analytics Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11.

PLUGIN Slimstat Analytics

CVE-2026-54818

HIGH CVSS 8.5 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54813 - SureDash Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects SureDash: from n/a through 1.8.0.

PLUGIN SureDash

CVE-2026-54813

HIGH CVSS 8.5 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54814 - Motors Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.

PLUGIN Motors

CVE-2026-54814

HIGH CVSS 8.1 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54816 - Advanced Ads Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.

PLUGIN Advanced Ads

CVE-2026-54816

HIGH CVSS 7.5 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54817 - MStore API Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.

PLUGIN MStore API

CVE-2026-54817

MEDIUM CVSS 6.5 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54809 - GIFT4U Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: from n/a through 1.0.10.

PLUGIN GIFT4U

CVE-2026-54809

CRITICAL CVSS 9.3 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-54808 - WP Travel Gutenberg Blocks Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.

PLUGIN WP Travel Gutenberg Blocks

CVE-2026-54808

CRITICAL CVSS 9.3 2026-06-17
Scroll to top