Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 1161-1180 of 18002 records
Threat Entry Updated 2026-06-17

CVE-2026-12360 - Jet Engine Plugin

The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row values within filtered_query are not sanitized before being merged into SQL construction. This makes it possible for unauthenticated attackers to perform time-based or boolean blind SQL injection by appending a malicious meta_query value to a Load More AJAX request captured from any public Listing Grid page.

PLUGIN Jet Engine

CVE-2026-12360

HIGH CVSS 7.5 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-12165 - Contest Gallery Plugin

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to the plugin's admin menu being registered at the `edit_posts` capability level — granting Contributor-level users access to the plugin's admin pages and a valid `cg_admin` nonce — while the option-saving handler in `change-options-and-sizes.php` performs no `current_user_can()` capability check beyond `check_admin_referer('cg_admin')`, and the `RegistryUserRole` value is processed only through `sanitize_text_field()` and `htmlentities()` without…

PLUGIN Contest Gallery

CVE-2026-12165

HIGH CVSS 8.8 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-12115 - Counter Box Plugin

The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via…

PLUGIN Counter Box

CVE-2026-12115

MEDIUM CVSS 6.6 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-40750 - Kids Online Store Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.

PLUGIN Kids Online Store

CVE-2026-40750

CRITICAL CVSS 9.9 2026-06-16
Threat Entry Updated 2026-06-17

CVE-2026-8442 - Wp Review Slider Pro Plugin

The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function, which uses strpos() to check that a stored media URL starts with the expected prefix but fails to sanitize path traversal sequences in the remaining relative path before passing it to unlink(). This makes it possible for authenticated attackers, with subscriber-level access and above, to delete…

PLUGIN Wp Review Slider Pro

CVE-2026-8442

HIGH CVSS 8.1 2026-06-16
Threat Entry Updated 2026-06-17

CVE-2026-8176 - Calendar Booking Plugin For Appointments And Events

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's password without ever invoking an Administrator-only API. This makes it possible for authenticated attackers, with Agent access and above, to elevate their privileges to Administrator.

PLUGIN Calendar Booking Plugin For Appointments And Events

CVE-2026-8176

HIGH CVSS 7.5 2026-06-16
Scroll to top