Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-6964 - Video Conferencing With Zoom Api Plugin
The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain the site's Zoom SDK API key and a freshly-signed JWT that can be used with the Zoom Web SDK to join any Zoom meeting associated with those credentials without a legitimate invitation.
CVE-2026-6964
CVE-2026-9691 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms
CVE-2026-9691
CVE-2026-52703 - WordPress component
Unauthenticated Path Traversal in FastDup
CVE-2026-52703
CVE-2026-52700 - WordPress component
Subscriber SQL Injection in WCMultiShipping
CVE-2026-52700
CVE-2026-52697 - WordPress component
Subscriber SQL Injection in Taskbuilder
CVE-2026-52697
CVE-2026-52699 - WordPress component
Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar
CVE-2026-52699
CVE-2026-52695 - WordPress component
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout
CVE-2026-52695
CVE-2026-52694 - WordPress component
Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce
CVE-2026-52694
CVE-2026-52702 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in SEO Redirection
CVE-2026-52702
CVE-2026-52693 - WordPress component
Unauthenticated SQL Injection in eCommerce Product Catalog
CVE-2026-52693
CVE-2026-52692 - WordPress component
Unauthenticated Sensitive Data Exposure in Affiliates Manager
CVE-2026-52692
CVE-2026-49781 - WordPress component
Unauthenticated PHP Object Injection in OttoKit
CVE-2026-49781
CVE-2026-49770 - WordPress component
Unauthenticated PHP Object Injection in WP Travel Engine
CVE-2026-49770
CVE-2026-49776 - WordPress component
Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites
CVE-2026-49776
CVE-2026-49780 - WordPress component
Customer Privilege Escalation in Dokan
CVE-2026-49780
CVE-2026-49775 - WordPress component
Unauthenticated Broken Access Control in Welcart e-Commerce
CVE-2026-49775
CVE-2026-49773 - WordPress component
Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.
CVE-2026-49773
CVE-2026-49766 - WordPress component
Subscriber Arbitrary File Deletion in WP User Manager
CVE-2026-49766
CVE-2026-49769 - WordPress component
Unauthenticated PHP Object Injection in wpForo Forum
CVE-2026-49769
CVE-2026-49768 - WordPress component
Unauthenticated PHP Object Injection in Happyforms
CVE-2026-49768
