Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-22338 - WordPress component
Unauthenticated Local File Inclusion in EcoBlue
CVE-2026-22338
CVE-2026-22334 - WordPress component
Subscriber Arbitrary File Download in Woocommerce Book Price
CVE-2026-22334
CVE-2026-22339 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in WPJobster
CVE-2026-22339
CVE-2026-22331 - WordPress component
Unauthenticated Local File Inclusion in AutoParts
CVE-2026-22331
CVE-2026-22330 - WordPress component
Unauthenticated Local File Inclusion in Right Way
CVE-2026-22330
CVE-2026-22327 - WordPress component
Subscriber Arbitrary File Upload in Restaurt
CVE-2026-22327
CVE-2026-22326 - WordPress component
Unauthenticated Local File Inclusion in Reprizo
CVE-2026-22326
CVE-2026-22325 - WordPress component
Unauthenticated Local File Inclusion in Promo
CVE-2026-22325
CVE-2026-22329 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Skillate
CVE-2026-22329
CVE-2026-22328 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Auto Repair
CVE-2026-22328
CVE-2026-12360 - Jet Engine Plugin
The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row values within filtered_query are not sanitized before being merged into SQL construction. This makes it possible for unauthenticated attackers to perform time-based or boolean blind SQL injection by appending a malicious meta_query value to a Load More AJAX request captured from any public Listing Grid page.
CVE-2026-12360
CVE-2026-12256 - WordPress component
Contributor PHP Object Injection in Avada
CVE-2026-12256
CVE-2026-12165 - Contest Gallery Plugin
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to the plugin's admin menu being registered at the `edit_posts` capability level — granting Contributor-level users access to the plugin's admin pages and a valid `cg_admin` nonce — while the option-saving handler in `change-options-and-sizes.php` performs no `current_user_can()` capability check beyond `check_admin_referer('cg_admin')`, and the `RegistryUserRole` value is processed only through `sanitize_text_field()` and `htmlentities()` without…
CVE-2026-12165
CVE-2026-12115 - Counter Box Plugin
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via…
CVE-2026-12115
CVE-2026-40750 - Kids Online Store Plugin
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.
CVE-2026-40750
CVE-2026-8442 - Wp Review Slider Pro Plugin
The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function, which uses strpos() to check that a stored media URL starts with the expected prefix but fails to sanitize path traversal sequences in the remaining relative path before passing it to unlink(). This makes it possible for authenticated attackers, with subscriber-level access and above, to delete…
CVE-2026-8442
CVE-2026-52715 - WordPress Core
Unauthenticated SQL Injection in GEO my WordPress
CVE-2026-52715
CVE-2026-8176 - Calendar Booking Plugin For Appointments And Events
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's password without ever invoking an Administrator-only API. This makes it possible for authenticated attackers, with Agent access and above, to elevate their privileges to Administrator.
CVE-2026-8176
CVE-2026-54198 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant
CVE-2026-54198
CVE-2026-54191 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Pods
CVE-2026-54191
