Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 101-120 of 18002 records
Threat Entry Updated 2026-07-16

CVE-2026-15445 - Seo Booster Plugin

The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Although esc_sql() and sanitize_text_field() are applied, neither neutralizes SQL keywords, commas, parentheses, or subquery syntax…

PLUGIN Seo Booster

CVE-2026-15445

MEDIUM CVSS 4.9 2026-07-16
Threat Entry Updated 2026-07-18

CVE-2026-13042 - Rpb Chessboard Plugin

The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's save-time kses sanitization does not mitigate this issue because the crafted payload uses only kses-allowed tags and attributes (such as an <a> element with title and href), and the dangerous attribute-breaking HTML is synthesized…

PLUGIN Rpb Chessboard

CVE-2026-13042

HIGH CVSS 7.2 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-15652 - Easy Accordion Free Plugin

The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Accordion Free

CVE-2026-15652

MEDIUM CVSS 6.4 2026-07-16
Threat Entry Updated 2026-07-17

CVE-2026-15336 - Catch Themes Demo Import Plugin

The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activate_plugin GET parameter is present, calling Plugin_Upgrader::install() to download and install a plugin from WordPress.org before performing the current_user_can('activate_plugins') capability check. This makes it possible for authenticated attackers, with subscriber-level access and above, to install the hardcoded 'essential-content-types' plugin from the WordPress.

PLUGIN Catch Themes Demo Import

CVE-2026-15336

MEDIUM CVSS 4.3 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-14987 - Donation Plugin And Fundraising Platform

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with give worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected script executes specifically when a donor clicks the Share on Twitter button on the Sequoia donation confirmation view, as that…

PLUGIN Donation Plugin And Fundraising Platform

CVE-2026-14987

MEDIUM CVSS 6.4 2026-07-16
Threat Entry Updated 2026-07-18

CVE-2026-12753 - Th Advance Product Search Plugin

The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Th Advance Product Search

CVE-2026-12753

HIGH CVSS 7.5 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12941 - Dc Woocommerce Multi Vendor Plugin

The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 5.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This vulnerability is exploitable by any authenticated subscriber-level user…

PLUGIN Dc Woocommerce Multi Vendor

CVE-2026-12941

MEDIUM CVSS 6.5 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-13005 - Mxchat Basic Plugin

The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Mxchat Basic

CVE-2026-13005

MEDIUM CVSS 4.4 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12434 - List Category Posts Plugin

The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles, full content, excerpts, dates, authors, and custom-field metadata of other users' pending-review, scheduled, and trashed posts by embedding a crafted [catlist] shortcode in their own draft and previewing it. This vulnerability is a bypass of the incomplete fix introduced for CVE-2025-11377 in version 0.93.0.

PLUGIN List Category Posts

CVE-2026-12434

MEDIUM CVSS 4.3 2026-07-16
Threat Entry Updated 2026-07-17

CVE-2026-12409 - Page Builder Add Plugin

The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. This makes it possible for unauthenticated attackers to create, update, retitle, or change the post status, slug, and type of arbitrary posts and write ULPB_DATA post meta via a forged request granted they can trick a site administrator into performing an action such as clicking…

PLUGIN Page Builder Add

CVE-2026-12409

MEDIUM CVSS 4.3 2026-07-16
Threat Entry Updated 2026-07-15

CVE-2026-12997 - Gravity Forms Plugin

The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the targeted form to not enforce login (so publicly accessible), which allows the unauthenticated attacker to reach the process_send_resume_link endpoint and supply an arbitrary recipient email address to receive the traversal-retrieved file as a notification attachment.

PLUGIN Gravity Forms

CVE-2026-12997

HIGH CVSS 7.5 2026-07-15
Threat Entry Updated 2026-07-15

CVE-2026-12512 - Quotes Llama Plugin

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform UNION-based SQL injection and read arbitrary data from the database, including password hashes.

PLUGIN Quotes Llama

CVE-2026-12512

HIGH CVSS 8.6 2026-07-15
Threat Entry Updated 2026-07-15

CVE-2026-12281 - Before 2 Plugin

The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an unauthenticated attacker can log in with forged identity headers and, when automatic account creation and the default administrator role mapping are enabled, create and sign in as a new administrator. Exploitation requires the non-default HTTP header attribute mode, an empty or absent spoof…

PLUGIN Before 2

CVE-2026-12281

HIGH CVSS 8.1 2026-07-15
Threat Entry Updated 2026-07-15

CVE-2026-11580 - Drag And Drop Builder Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own and read its private post metadata, including secrets stored by other Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17.

PLUGIN Drag And Drop Builder

CVE-2026-11580

MEDIUM CVSS 5.5 2026-07-15
Threat Entry Updated 2026-07-15

CVE-2026-11579 - Drag And Drop Builder Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress Media Library; the uploads are limited to WordPress's default-allowed MIME types, so this does not lead to code execution.

PLUGIN Drag And Drop Builder

CVE-2026-11579

MEDIUM CVSS 5.3 2026-07-15
Threat Entry Updated 2026-07-14

CVE-2026-13001 - Podlove Podcasting Plugin For Wordpress

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Podlove Podcasting Plugin For Wordpress

CVE-2026-13001

CRITICAL CVSS 9.8 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-9341 - Wordpress Lms Plugin For Complete Elearning Solution

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.0 via the 'save_lesson_note', 'get_lesson_note', and 'complete_lesson_video' AJAX handlers due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read, overwrite, or delete the private lesson notes of any other user (including administrators), and to falsify lesson-completion progress for arbitrary users.

PLUGIN Wordpress Lms Plugin For Complete Elearning Solution

CVE-2026-9341

MEDIUM CVSS 4.3 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-12988 - Wp 2fa Plugin

The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled email address and take over the account.

PLUGIN Wp 2fa

CVE-2026-12988

MEDIUM CVSS 6.4 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-12583 - Via A Property Oriented Gadget Chain Bundled With The Newsletters Plugin

The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and execute code on the server.

PLUGIN Via A Property Oriented Gadget Chain Bundled With The Newsletters

CVE-2026-12583

HIGH CVSS 8.1 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-12511 - Ai Engine Plugin

The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.

PLUGIN Ai Engine

CVE-2026-12511

HIGH CVSS 8.1 2026-07-14
Scroll to top