Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-8089 - Email Optins For Woocommerce Plugin
The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrators) via a crafted URL.
CVE-2026-8089
CVE-2026-7850 - Wp Magnific Popup Plugin
The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks against any visiting user.
CVE-2026-7850
CVE-2026-54807 - WordPress component
Unauthenticated Privilege Escalation in Registration Form for WooCommerce
CVE-2026-54807
CVE-2026-54806 - WordPress component
Unauthenticated PHP Object Injection in WP Activity Log
CVE-2026-54806
CVE-2026-54803 - WordPress component
Subscriber Privilege Escalation in SMS Alert Order Notifications
CVE-2026-54803
CVE-2026-54811 - WordPress component
Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.
CVE-2026-54811
CVE-2026-54805 - WordPress component
Subscriber Privilege Escalation in Falang multilanguage
CVE-2026-54805
CVE-2026-54804 - WordPress component
Subscriber Broken Authentication in Melhor Envio
CVE-2026-54804
CVE-2026-54802 - WordPress component
Unauthenticated Broken Authentication in SMS Alert Order Notifications
CVE-2026-54802
CVE-2026-54194 - WordPress component
Contributor PHP Object Injection in Fusion Builder
CVE-2026-54194
CVE-2026-54187 - WordPress component
Unauthenticated SQL Injection in JetEngine
CVE-2026-54187
CVE-2026-54195 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder
CVE-2026-54195
CVE-2026-54192 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Popup box
CVE-2026-54192
CVE-2026-54189 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in JetEngine
CVE-2026-54189
CVE-2026-54188 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in JetEngine
CVE-2026-54188
CVE-2026-54196 - WordPress component
Subscriber Privilege Escalation in JetFormBuilder
CVE-2026-54196
CVE-2026-52706 - WordPress component
Unauthenticated PHP Object Injection in JetEngine
CVE-2026-52706
CVE-2026-54186 - WordPress component
Unauthenticated SQL Injection in JobSearch
CVE-2026-54186
CVE-2026-52705 - WordPress component
Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms
CVE-2026-52705
CVE-2026-54185 - WordPress component
Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
CVE-2026-54185
