Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 1401-1420 of 18002 records
Threat Entry Updated 2026-06-17

CVE-2026-9278 - Form Builder Cp Plugin

The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page rendering the affected form, even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).

PLUGIN Form Builder Cp

CVE-2026-9278

MEDIUM CVSS 5.4 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-8386 - Wp Go Maps Plugin

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.

PLUGIN Wp Go Maps

CVE-2026-8386

MEDIUM CVSS 5.3 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-8385 - Wp Go Maps Plugin

The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing unauthenticated visitors to retrieve marker records that the site owner has not approved for public display, including their title, category, address and description fields.

PLUGIN Wp Go Maps

CVE-2026-8385

MEDIUM CVSS 5.3 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-5513 - Online Scheduling and Appointment Booking System – Bookly Plugin

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires 'Remember personal information in cookies' setting to be enabled (disabled by default).

PLUGIN Online Scheduling and Appointment Booking System – Bookly

CVE-2026-5513

HIGH CVSS 7.2 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-1291 - Meow Gallery Plugin

The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint /wp-json/meow-gallery/v1/save_shortcode in all versions up to, and including, 5.4.4 This makes it possible for authenticated attackers, with Author-level access and above, to arbitrarily create or overwrite existing gallery shortcode records by supplying a user-controlled id value. The endpoint performs database update operations without verifying that the requesting user is authorized to modify the referenced gallery record or create their own.

PLUGIN Meow Gallery

CVE-2026-1291

MEDIUM CVSS 4.3 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9629 - Canvas Plugin

The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Canvas

CVE-2026-9629

MEDIUM CVSS 6.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-3297 - Drag And Drop Website Builder Plugin

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Drag And Drop Website Builder

CVE-2026-3297

MEDIUM CVSS 6.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-2470 - Drag And Drop Website Builder Plugin

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due to the pagelayer_save_content AJAX handler allowing users with basic post-edit capability to persist pagelayer_contact_templates metadata on posts they can edit (including pending posts), while the unauthenticated pagelayer_contact_submit endpoint later consumes that metadata by user-controlled post/form identifiers without enforcing a privileged or published-context boundary. This makes it possible for authenticated attackers, with Contributor-level access and above, to configure arbitrary contact-form mail templates…

PLUGIN Drag And Drop Website Builder

CVE-2026-2470

MEDIUM CVSS 4.3 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9134 - Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel Plugin

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of HTML event attributes (onmouseover, onmouseout, onpointerenter, onclick, onload, onchange, onerror) while permitting others such as 'onmouseenter', combined with the failure to escape the attribute key when building the gallery container HTML in foogallery_build_container_attributes_safe(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject…

PLUGIN Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

CVE-2026-9134

MEDIUM CVSS 6.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9109 - Automatically Translate Websites Plugin

The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Translation Storage in all versions up to, and including, 2.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The deterministically derived API key (sha256 of the site URL) is printed in the HTML source of every page via the JavaScript variable gptApiKey, meaning…

PLUGIN Automatically Translate Websites

CVE-2026-9109

HIGH CVSS 7.2 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9061 - Store Locator Plugin

The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin before 1.6.9 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).

PLUGIN Store Locator

CVE-2026-9061

LOW CVSS 3.5 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9062 - Store Locator Plugin

The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.

PLUGIN Store Locator

CVE-2026-9062

LOW CVSS 3.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9848 - Customer Support Ticket System & Helpdesk Plugin

The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.0.4 The plugin hooks WordPress's `posts_request` filter with `wp_ticket_com_posts_request()`, which calls `emd_author_search_results()` when the current request is an unauthenticated front-end search. That function reads `$query->query_vars['s']` — already wp_unslash()'d by `WP_Query::parse_query()`, so wp_magic_quotes protection has been stripped — and concatenates the raw value into a SQL `LIKE` clause inside a UNION sub-SELECT appended to the main query, with no `$wpdb->prepare()` or escaping. This makes it possible for…

PLUGIN Customer Support Ticket System & Helpdesk

CVE-2026-9848

HIGH CVSS 7.5 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-12089 - Lws Optimize Plugin

The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combine_current_css() function trusting values harvested from page HTML and converting same-site URLs to absolute filesystem paths before reading them with file_get_contents()/Minify\CSS::add(), without enforcing that the resolved path stay within ABSPATH or have a .css extension. This makes it possible for authenticated attackers, with Editor-level access and above, to read arbitrary files.

PLUGIN Lws Optimize

CVE-2026-12089

MEDIUM CVSS 4.9 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-24618 - Hash Elements Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data. This issue affects Hash Elements: from n/a through 1.5.4.

PLUGIN Hash Elements

CVE-2026-24618

MEDIUM CVSS 4.3 2026-06-12
Threat Entry Updated 2026-06-17

CVE-2026-9269 - Secure Copy Content Protection And Content Locking Plugin

The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Secure Copy Content Protection And Content Locking

CVE-2026-9269

LOW CVSS 3.5 2026-06-12
Threat Entry Updated 2026-06-17

CVE-2026-47365 - WordPress-Toolkit Plugin

Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.

PLUGIN WordPress-Toolkit

CVE-2026-47365

CRITICAL CVSS 9.9 2026-06-12
Threat Entry Updated 2026-06-17

CVE-2026-9125 - Presto Player Plugin

The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url shortcode attribute directly into the overlay configuration without scheme validation, allowing javascript: URIs to survive and be rendered as the href of a clickable anchor element by the presto-dynamic-overlay-ui web component. This makes it possible for authenticated attackers, with contributor-level access and above, to inject…

PLUGIN Presto Player

CVE-2026-9125

MEDIUM CVSS 6.4 2026-06-12
Threat Entry Updated 2026-06-17

CVE-2026-42647 - JoomSport Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7.

PLUGIN JoomSport

CVE-2026-42647

CRITICAL CVSS 9.3 2026-06-11
Scroll to top