Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,222
Critical1,269
High4,352
Medium12,378
Reset
Showing 1781-1800 of 18222 records
Threat Entry Updated 2026-07-22

CVE-2026-3722 - Auto Image Attributes From Filename With Bulk Updater Plugin

The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment metadata in all versions up to, and including, 4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Auto Image Attributes From Filename With Bulk Updater

CVE-2026-3722

MEDIUM CVSS 6.4 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-10100 - Simple Custom Login Page Plugin

The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, Link Color) in versions up to and including 1.0.3. This is due to insufficient input sanitization of the color option values (they were registered with register_setting() and stored via the Settings API/update_option() with no sanitize_callback) combined with the values being output into a block on wp-login.php using esc_attr(), which is incorrect for a CSS context (it does not escape ;, {, }, / or *).…

PLUGIN Simple Custom Login Page

CVE-2026-10100

MEDIUM CVSS 4.4 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-9050 - Slider Revolution Plugin

The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to deactivate any active plugin installed on the site.

PLUGIN Slider Revolution

CVE-2026-9050

MEDIUM CVSS 4.3 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-9048 - Slider Revolution Plugin

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw social media API credentials: the Instagram OAuth token, Flickr API key, YouTube Data API key, and Facebook App ID, stored in any configured slider's settings.

PLUGIN Slider Revolution

CVE-2026-9048

MEDIUM CVSS 4.3 2026-06-02
Threat Entry Updated 2026-07-22

CVE-2026-42677 - WP Document Revisions Plugin

Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0.

PLUGIN WP Document Revisions

CVE-2026-42677

HIGH CVSS 7.5 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-42675 - Hydra Booking Plugin

Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hydra Booking: from n/a through 1.1.41.

PLUGIN Hydra Booking

CVE-2026-42675

HIGH CVSS 7.3 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-42678 - GiveWP Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from n/a through 4.14.5.

PLUGIN GiveWP

CVE-2026-42678

HIGH CVSS 7.1 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-42679 - Classified Listing Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8.

PLUGIN Classified Listing

CVE-2026-42679

MEDIUM CVSS 6.5 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-42676 - myCred Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects myCred: from n/a through 3.0.4.

PLUGIN myCred

CVE-2026-42676

MEDIUM CVSS 6.5 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-42672 - WP Directory Kit Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.1.

PLUGIN WP Directory Kit

CVE-2026-42672

CRITICAL CVSS 9.3 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-42673 - Activity Logs, User Activity Tracking, Multisite Activity Log Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a through 3.3.6.

PLUGIN Activity Logs, User Activity Tracking, Multisite Activity Log

CVE-2026-42673

HIGH CVSS 7.5 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-42671 - GeoDirectory Plugin

Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.

PLUGIN GeoDirectory

CVE-2026-42671

MEDIUM CVSS 6.5 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-48879 - AIWU Plugin

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

PLUGIN AIWU

CVE-2026-48879

CRITICAL CVSS 9.8 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-48866 - Gravity Forms Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1.

PLUGIN Gravity Forms

CVE-2026-48866

CRITICAL CVSS 9.6 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-48865 - LearnPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS. This issue affects LearnPress: from n/a through 4.3.6.

PLUGIN LearnPress

CVE-2026-48865

HIGH CVSS 7.1 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-48839 - WP Statistics Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6.

PLUGIN WP Statistics

CVE-2026-48839

HIGH CVSS 7.1 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-42682 - wpForo Forum Plugin

Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.

PLUGIN wpForo Forum

CVE-2026-42682

CRITICAL CVSS 9.1 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-42683 - VikBooking Hotel Booking Engine & PMS Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows DOM-Based XSS. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.8.

PLUGIN VikBooking Hotel Booking Engine & PMS

CVE-2026-42683

HIGH CVSS 7.1 2026-06-01
Threat Entry Updated 2026-07-22

CVE-2026-42680 - Contest Gallery Pro Plugin

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.

PLUGIN Contest Gallery Pro

CVE-2026-42680

CRITICAL CVSS 9.8 2026-06-01
Scroll to top