Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-34902 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite
CVE-2026-34902
CVE-2026-34900 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in GiveWP
CVE-2026-34900
CVE-2026-34898 - WordPress component
Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce
CVE-2026-34898
CVE-2026-34891 - WordPress component
Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce
CVE-2026-34891
CVE-2026-34886 - WordPress component
Unauthenticated Broken Access Control in Simple Membership
CVE-2026-34886
CVE-2026-27407 - WordPress component
Editor Privilege Escalation in AI Engine
CVE-2026-27407
CVE-2026-34892 - WordPress component
Subscriber Broken Access Control in Rank Math SEO
CVE-2026-34892
CVE-2026-27053 - WordPress component
Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
CVE-2026-27053
CVE-2026-24637 - WordPress component
Contributor SQL Injection in PowerPress Podcasting
CVE-2026-24637
CVE-2026-27333 - WordPress component
Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site
CVE-2026-27333
CVE-2026-27089 - WordPress component
Unauthenticated Bypass Vulnerability in WpTravelly
CVE-2026-27089
CVE-2026-25425 - WordPress component
Unauthenticated Broken Access Control in User Registration
CVE-2026-25425
CVE-2026-23970 - Contact Form 7 Plugin
Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7
CVE-2026-23970
CVE-2026-25440 - Elementor Plugin
Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.
CVE-2026-25440
CVE-2026-52704 - WooCommerce PDF Invoice Builder Plugin
Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.
CVE-2026-52704
CVE-2026-49111 - Masteriyo - LMS Plugin
Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.
CVE-2026-49111
CVE-2026-49062 - Faust.Js Plugin
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.
CVE-2026-49062
CVE-2026-49064 - GetPaid Plugin
Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.
CVE-2026-49064
CVE-2026-48969 - WordPress component
Subscriber Broken Access Control in Really Simple SSL
CVE-2026-48969
CVE-2026-8935 - Wp Maps Pro Plugin
The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.
CVE-2026-8935
