Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-49108 - WordPress component
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
CVE-2026-49108
CVE-2026-40757 - WordPress component
Unauthenticated PHP Object Injection in Château
CVE-2026-40757
CVE-2026-40756 - WordPress component
Unauthenticated PHP Object Injection in Zoya
CVE-2026-40756
CVE-2026-40752 - WordPress component
Unauthenticated PHP Object Injection in Manufaktur Solutions
CVE-2026-40752
CVE-2026-40738 - WordPress component
Unauthenticated PHP Object Injection in Eldon
CVE-2026-40738
CVE-2026-40733 - WordPress component
Unauthenticated PHP Object Injection in ShiftUp
CVE-2026-40733
CVE-2026-39590 - WordPress component
Unauthenticated Local File Inclusion in Atomlab
CVE-2026-39590
CVE-2026-39576 - WordPress component
Unauthenticated PHP Object Injection in SingleMalt
CVE-2026-39576
CVE-2026-39560 - WordPress component
Unauthenticated PHP Object Injection in Hiroshi
CVE-2026-39560
CVE-2026-39559 - WordPress component
Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.
CVE-2026-39559
CVE-2026-39556 - WordPress component
Unauthenticated PHP Object Injection in Konsept
CVE-2026-39556
CVE-2026-40720 - Elementor Plugin
Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.
CVE-2026-40720
CVE-2026-39523 - WordPress component
Unauthenticated Local File Inclusion in Solene Core
CVE-2026-39523
CVE-2026-39445 - WordPress component
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
CVE-2026-39445
CVE-2026-39442 - WordPress component
Unauthenticated PHP Object Injection in PressMart
CVE-2026-39442
CVE-2026-9690 - WordPress component
Unauthenticated Arbitrary File Download in WP Media folder Addon
CVE-2026-9690
CVE-2026-9570 - Before 5 Plugin
The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any logged-in user.
CVE-2026-9570
CVE-2026-8607 - Mycred Plugin
The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-8607
CVE-2026-8494 - Permalink Manager Plugin
The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in the admin Permalink Manager page that will execute whenever an administrator accesses the Permalink Manager page.
CVE-2026-8494
CVE-2026-8383 - Before 4 Plugin
The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request
CVE-2026-8383
