Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-34895 - WordPress component
Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions.
CVE-2026-34895
CVE-2026-34894 - WordPress component
Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versions.
CVE-2026-34894
CVE-2026-34893 - WordPress component
Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions.
CVE-2026-34893
CVE-2026-34888 - WordPress component
Unauthenticated Sensitive Data Exposure in Bricksforge
CVE-2026-34888
CVE-2026-27429 - WordPress component
Unauthenticated PHP Object Injection in Nifty
CVE-2026-27429
CVE-2026-27041 - Elementor Plugin
Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium)
CVE-2026-27041
CVE-2026-27395 - WordPress component
Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
CVE-2026-27395
CVE-2026-27400 - WordPress component
Unauthenticated Arbitrary File Deletion in BookPro
CVE-2026-27400
CVE-2026-27410 - WordPress component
Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.
CVE-2026-27410
CVE-2026-25470 - Custom Post Types Plugin
Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.
CVE-2026-25470
CVE-2026-25446 - WordPress component
Subscriber Arbitrary File Upload in WishList Member X
CVE-2026-25446
CVE-2026-25439 - WordPress component
Unauthenticated Broken Authentication in Booknetic
CVE-2026-25439
CVE-2026-24611 - WordPress component
Unauthenticated Broken Access Control in MetForm Pro
CVE-2026-24611
CVE-2026-24610 - WordPress component
Subscriber Broken Access Control in MetForm Pro
CVE-2026-24610
CVE-2026-24575 - WordPress component
Subscriber Broken Access Control in WishList Member X
CVE-2026-24575
CVE-2026-22343 - WordPress component
Unauthenticated Broken Access Control in WordPress Dating Theme
CVE-2026-22343
CVE-2026-22340 - WordPress component
Unauthenticated SQL Injection in WPJobster
CVE-2026-22340
CVE-2026-22332 - WordPress component
Unauthenticated SQL Injection in Tutor LMS Pro
CVE-2026-22332
CVE-2026-22342 - WordPress component
Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme
CVE-2026-22342
CVE-2026-22335 - WordPress component
Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.
CVE-2026-22335
