Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 121-140 of 18002 records
Threat Entry Updated 2026-07-14

CVE-2026-11567 - Before 2 Plugin

The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden) payment amount, allowing unauthenticated users to underpay for the configured product or subscription. Forms using a fixed configured price are not affected.

PLUGIN Before 2

CVE-2026-11567

MEDIUM CVSS 5.9 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-11563 - Word Count And Social Shares Plugin

The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g. by deleting wp-config.php).

PLUGIN Word Count And Social Shares

CVE-2026-11563

CRITICAL CVSS 9.6 2026-07-14
Threat Entry Updated 2026-07-15

CVE-2026-7640 - Customer Area Plugin

The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-content` shortcode in all versions up to, and including, 8.3.5. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Customer Area

CVE-2026-7640

MEDIUM CVSS 6.4 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-11390 - News Kit Elementor Addons Plugin

The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an attacker to intercept and modify the elementor_ajax AJAX save request in order to bypass the client-side SELECT control…

PLUGIN News Kit Elementor Addons

CVE-2026-11390

MEDIUM CVSS 6.4 2026-07-14
Threat Entry Updated 2026-07-15

CVE-2026-11802 - Foodbook Light Online Food Ordering System Plugin

The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.6. The registration() function, accessible via the wp_ajax_nopriv_registration_action AJAX action, lacks any nonce verification or capability check, and does not check the WordPress users_can_register option before calling wp_insert_user(). This makes it possible for unauthenticated attackers to create new user accounts with the 'customer' role and receive authentication cookies, even when the site administrator has explicitly disabled user registration.

PLUGIN Foodbook Light Online Food Ordering System

CVE-2026-11802

MEDIUM CVSS 5.3 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-12536 - Builder Plugin

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Module Title’ parameter in all versions up to, and including, 3.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Builder

CVE-2026-12536

MEDIUM CVSS 6.4 2026-07-13
Threat Entry Updated 2026-07-14

CVE-2026-12385 - Smart Slider 3 Plugin

The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles and full content excerpts of private, draft, pending, trashed, and auto-draft posts authored by any user, including Administrators and Editors. The required nonce is emitted on /wp-admin/post-new.php, which is accessible to Contributor-level users via the edit_posts capability, meaning any Contributor can obtain the nonce needed to trigger the injection.

PLUGIN Smart Slider 3

CVE-2026-12385

MEDIUM CVSS 4.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61985 - Car Rental Manager Plugin

Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through

PLUGIN Car Rental Manager

CVE-2026-61985

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61983 - Church Admin Plugin

Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through

PLUGIN Church Admin

CVE-2026-61983

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61977 - JetSearch Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through

PLUGIN JetSearch

CVE-2026-61977

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61976 - Elementor Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through

PLUGIN Elementor

CVE-2026-61976

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61975 - JetReviews Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through

PLUGIN JetReviews

CVE-2026-61975

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61971 - User Profile Picture Plugin

Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through

PLUGIN User Profile Picture

CVE-2026-61971

LOW CVSS 2.7 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61955 - WordPress component Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through

PLUGIN WordPress component

CVE-2026-61955

HIGH CVSS 7.6 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-59521 - Real Testimonials Plugin

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through

PLUGIN Real Testimonials

CVE-2026-59521

HIGH CVSS 7.2 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61956 - ووسلام – همگام سازی ووکامرس و باسلام Plugin

Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام – همگام سازی ووکامرس و باسلام: from n/a through

PLUGIN ووسلام – همگام سازی ووکامرس و باسلام

CVE-2026-61956

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-59523 - Simply Schedule Appointments Plugin

Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through

PLUGIN Simply Schedule Appointments

CVE-2026-59523

MEDIUM CVSS 6.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61968 - myCred Plugin

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through

PLUGIN myCred

CVE-2026-61968

MEDIUM CVSS 5.4 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61958 - License Manager for WooCommerce Plugin

Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through

PLUGIN License Manager for WooCommerce

CVE-2026-61958

MEDIUM CVSS 5.4 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-61970 - Auto Featured Image (Auto Post Thumbnail Plugin

Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through

PLUGIN Auto Featured Image (Auto Post Thumbnail

CVE-2026-61970

MEDIUM CVSS 4.9 2026-07-13
Scroll to top