Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,222
Critical1,269
High4,352
Medium12,378
Reset
Showing 1741-1760 of 18222 records
Threat Entry Updated 2026-07-22

CVE-2026-8653 - MasterStudy LMS Pro Theme

The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with instructor-level access or above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

THEME MasterStudy LMS Pro

CVE-2026-8653

MEDIUM CVSS 6.5 2026-06-04
Threat Entry Updated 2026-07-22

CVE-2026-9732 - Legacy Deliverance Plugin

The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the form_settings_ui (settings save handler, procedural include scope) function. This makes it possible for unauthenticated attackers to modify plugin settings including the minimum access role (altering WordPress role capabilities via add_cap/remove_cap), the data-erasure-on-uninstall flag, life-check timing values, the mandator email address, the confirmation page ID, and date/time formats via a forged request granted they…

PLUGIN Legacy Deliverance

CVE-2026-9732

MEDIUM CVSS 4.3 2026-06-03
Threat Entry Updated 2026-07-21

CVE-2026-7421 - Passeum Ticketing Plugin

The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name` setting value without sanitization when it begins with "http", combined with insufficient validation in the `validate_shop_name()` function which only checks for empty values and string type. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary external scripts by setting the `shop_name` to an attacker-controlled URL (e.g., `https://attacker.com`), which causes the plugin to enqueue external…

PLUGIN Passeum Ticketing

CVE-2026-7421

MEDIUM CVSS 4.4 2026-06-03
Threat Entry Updated 2026-07-21

CVE-2026-5076 - ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a password reset. This is in addition to the hashed key that WordPress core stores securely in `wp_users.user_activation_key`. The plaintext key stored in `wp_usermeta` can be used with the plugin's custom `armrp` reset action to set a new password for any user. Combined with another vulnerability such…

PLUGIN ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

CVE-2026-5076

CRITICAL CVSS 9.8 2026-06-02
Threat Entry Updated 2026-07-21

CVE-2026-5073 - ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient escaping on the user-supplied 'order' and 'orderby' parameters and the lack of sufficient preparation on the existing SQL query in the `arm_get_directory_members()` function. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

CVE-2026-5073

HIGH CVSS 7.5 2026-06-02
Threat Entry Updated 2026-07-21

CVE-2026-5074 - ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient sanitization of the user-supplied parameter which is concatenated directly into the ORDER BY clause of an SQL query without a whitelist check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note: The vulnerability…

PLUGIN ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

CVE-2026-5074

MEDIUM CVSS 6.5 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-1829 - Content Visibility For Divi Builder Plugin

The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

PLUGIN Content Visibility For Divi Builder

CVE-2026-1829

HIGH CVSS 8.8 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-0611 - WordPress component

Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI endpoints. Attackers can write ASPX webshells to the IIS wwwroot directory to achieve unauthenticated remote code execution on the system. Port 8989 is not exposed in a default Sentinel installation; exploitation requires that the .NET Remoting port has been explicitly made network-accessible through deliberate configuration…

UNKNOWN WordPress component

CVE-2026-0611

CRITICAL CVSS 9.2 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-42654 - Wallet System for WooCommerce Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5.

PLUGIN Wallet System for WooCommerce

CVE-2026-42654

HIGH CVSS 7.1 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-40780 - BookIt Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation. This issue affects BookIt: from n/a before 2.5.4.1.

PLUGIN BookIt

CVE-2026-40780

HIGH CVSS 7.5 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-49782 - Elementor Plugin

Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through 4.1.0.

PLUGIN Elementor

CVE-2026-49782

MEDIUM CVSS 5.4 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-39555 - Askka Plugin

Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1.

PLUGIN Askka

CVE-2026-39555

HIGH CVSS 8.1 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-39553 - WaveRide Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allows PHP Local File Inclusion. This issue affects WaveRide: from n/a through 1.4.

PLUGIN WaveRide

CVE-2026-39553

HIGH CVSS 8.1 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-39552 - Blueprint Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5.

PLUGIN Blueprint

CVE-2026-39552

HIGH CVSS 8.1 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-28116 - Progress Planner Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored XSS. This issue affects Progress Planner: from n/a through 1.9.0.

PLUGIN Progress Planner

CVE-2026-28116

MEDIUM CVSS 5.9 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-27351 - Crew HRM Plugin

Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crew HRM: from n/a through 1.2.2.

PLUGIN Crew HRM

CVE-2026-27351

MEDIUM CVSS 5.4 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-42684 - WP Job Portal Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1.

PLUGIN WP Job Portal

CVE-2026-42684

CRITICAL CVSS 9.3 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-39551 - Töbel Plugin

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.

PLUGIN Töbel

CVE-2026-39551

HIGH CVSS 8.1 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-39550 - Aperitif Plugin

Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.

PLUGIN Aperitif

CVE-2026-39550

HIGH CVSS 8.1 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-42670 - Five Star Restaurant Reservations Plugin

Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14.

PLUGIN Five Star Restaurant Reservations

CVE-2026-42670

HIGH CVSS 7.5 2026-06-02
Scroll to top