Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,225
Critical1,270
High4,356
Medium12,382
Reset
Showing 1961-1980 of 18225 records
Threat Entry Updated 2026-06-17

CVE-2026-8048 - My Email Shortcode Plugin

The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shortcode in all versions up to, and including, 0.91 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN My Email Shortcode

CVE-2026-8048

MEDIUM CVSS 6.4 2026-05-27
Threat Entry Updated 2026-06-17

CVE-2026-8707 - Product Icon Badge Plugin

The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Product Icon Badge

CVE-2026-8707

MEDIUM CVSS 6.1 2026-05-27
Threat Entry Updated 2026-06-17

CVE-2026-8708 - Genzel Breadcrumbs Plugin

The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the _options_page function. This makes it possible for unauthenticated attackers to update the plugin's breadcrumb configuration, including templates, delimiter, home label, home URI, and breadcrumb rules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Genzel Breadcrumbs

CVE-2026-8708

MEDIUM CVSS 4.3 2026-05-27
Threat Entry Updated 2026-06-17

CVE-2026-8040 - Faq Shortcode Plugin

The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in the 'faq' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Faq Shortcode

CVE-2026-8040

MEDIUM CVSS 6.4 2026-05-27
Threat Entry Updated 2026-06-17

CVE-2026-7614 - Old Posts Highlighter Plugin

The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the OPH_options function. This makes it possible for unauthenticated attackers to update the plugin's configuration settings without authorization via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Old Posts Highlighter

CVE-2026-7614

MEDIUM CVSS 4.3 2026-05-27
Threat Entry Updated 2026-06-17

CVE-2026-6268 - Before 22 Theme

The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against logged-in users.

THEME Before 22

CVE-2026-6268

HIGH CVSS 7.1 2026-05-27
Threat Entry Updated 2026-07-23

CVE-2026-9236 - CM Ad Changer – A simple tool to control and optimize your site's banners Plugin

The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the cmac_campaigns_action function. This makes it possible for unauthenticated attackers to permanently delete arbitrary advertising campaigns, including their associated banner records and uploaded files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN CM Ad Changer – A simple tool to control and optimize your site's banners

CVE-2026-9236

MEDIUM CVSS 4.3 2026-05-27
Threat Entry Updated 2026-07-24

CVE-2026-6287 - ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple Product Gride blocks in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

CVE-2026-6287

MEDIUM CVSS 5.4 2026-05-27
Threat Entry Updated 2026-07-23

CVE-2026-9022 - Splide Carousel Block Plugin

The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload must be published before it executes for site visitors, which requires an editor or administrator to approve and publish the contributor's post.

PLUGIN Splide Carousel Block

CVE-2026-9022

MEDIUM CVSS 6.4 2026-05-27
Threat Entry Updated 2026-07-24

CVE-2026-6565 - Style Kits for Elementor Plugin

The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endpoint kit title parameter in versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping in an admin attribute context. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Style Kits for Elementor

CVE-2026-6565

MEDIUM CVSS 6.4 2026-05-27
Threat Entry Updated 2026-07-23

CVE-2026-7493 - Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function on a user-supplied delay parameter without any rate limiting. This makes it possible for unauthenticated attackers to exhaust PHP worker processes, denying access to the site to legitimate users.

PLUGIN Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

CVE-2026-7493

MEDIUM CVSS 5.3 2026-05-27
Threat Entry Updated 2026-07-24

CVE-2026-27331 - WpTravelly Plugin

Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5.

PLUGIN WpTravelly

CVE-2026-27331

MEDIUM CVSS 6.3 2026-05-26
Threat Entry Updated 2026-07-24

CVE-2026-25426 - Taxi Booking Manager for WooCommerce Plugin

Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.1.

PLUGIN Taxi Booking Manager for WooCommerce

CVE-2026-25426

MEDIUM CVSS 5.3 2026-05-26
Threat Entry Updated 2026-07-24

CVE-2026-25444 - WpBookingly Plugin

Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.

PLUGIN WpBookingly

CVE-2026-25444

MEDIUM CVSS 4.3 2026-05-26
Threat Entry Updated 2026-07-24

CVE-2026-24520 - Tiktok Feed Plugin

Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tiktok Feed: from n/a through 1.0.24.

PLUGIN Tiktok Feed

CVE-2026-24520

MEDIUM CVSS 4.3 2026-05-26
Threat Entry Updated 2026-07-23

CVE-2026-8174 - Zoho Mail Plugin

Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2.

PLUGIN Zoho Mail

CVE-2026-8174

MEDIUM CVSS 5.7 2026-05-26
Threat Entry Updated 2026-07-24

CVE-2026-39661 - SW Core Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This issue affects SW Core: from n/a through 1.7.18.

PLUGIN SW Core

CVE-2026-39661

HIGH CVSS 7.5 2026-05-26
Threat Entry Updated 2026-07-24

CVE-2026-39642 - Nyla Plugin

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a through 1.7.

PLUGIN Nyla

CVE-2026-39642

MEDIUM CVSS 5.3 2026-05-26
Threat Entry Updated 2026-07-24

CVE-2026-27427 - Geo Mashup Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This issue affects Geo Mashup: from n/a through 1.13.18.

PLUGIN Geo Mashup

CVE-2026-27427

MEDIUM CVSS 6.5 2026-05-26
Threat Entry Updated 2026-07-24

CVE-2026-24590 - Paid Videochat Turnkey Site Plugin

Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.23.

PLUGIN Paid Videochat Turnkey Site

CVE-2026-24590

MEDIUM CVSS 5.3 2026-05-26
Scroll to top