CVE Database

134505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-6801
5.3 MEDIUM

The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup. This makes …

Jul 11, 2026
CVE-2026-4661
7.5 HIGH

The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter …

Jul 11, 2026
CVE-2026-1382
6.4 MEDIUM

The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and including, 1.0.7 due …

Jul 11, 2026
CVE-2026-15155
8.8 HIGH

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in …

Jul 11, 2026
CVE-2026-15010
6.4 MEDIUM

The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional …

Jul 11, 2026
CVE-2026-12994
5.3 MEDIUM

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. This is …

Jul 11, 2026
CVE-2026-12738
4.3 MEDIUM

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Jul 11, 2026
CVE-2026-12126
6.4 MEDIUM

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, …

Jul 11, 2026
CVE-2026-12103
4.3 MEDIUM

The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the …

Jul 11, 2026
CVE-2026-11901
5.3 MEDIUM

The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is …

Jul 11, 2026
CVE-2026-11898
4.4 MEDIUM

The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due …

Jul 11, 2026
CVE-2026-11591
4.4 MEDIUM

The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 …

Jul 11, 2026
CVE-2026-10865
5.3 MEDIUM

The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). …

Jul 11, 2026
CVE-2026-10041
4.3 MEDIUM

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 …

Jul 11, 2026
CVE-2025-6784
8.8 HIGH

The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This …

Jul 11, 2026
CVE-2025-5017
4.9 MEDIUM

The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, …

Jul 11, 2026
CVE-2026-7655
8.1 HIGH

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the …

Jul 11, 2026
CVE-2026-13378
7.2 HIGH

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all …

Jul 11, 2026
CVE-2026-9738
4.4 MEDIUM

The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and …

Jul 11, 2026
CVE-2026-7620
4.3 MEDIUM

The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. This is due to the …

Jul 11, 2026
CVE-2026-7559
4.3 MEDIUM

The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, …

Jul 11, 2026
CVE-2026-6804
5.3 MEDIUM

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This …

Jul 11, 2026
CVE-2026-6803
5.3 MEDIUM

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This …

Jul 11, 2026
CVE-2026-3576
7.2 HIGH

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and …

Jul 11, 2026
CVE-2026-3552
4.3 MEDIUM

The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function …

Jul 11, 2026
CVE-2026-2354
8.8 HIGH

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` …

Jul 11, 2026
CVE-2026-1832
4.3 MEDIUM

The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cache deletion due to a missing capability …

Jul 11, 2026
CVE-2026-15335
7.5 HIGH

The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 …

Jul 11, 2026
CVE-2026-15097
6.4 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6 …

Jul 11, 2026
CVE-2026-15096
6.4 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 …

Jul 11, 2026
CVE-2026-14262
8.8 HIGH

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in …

Jul 11, 2026
CVE-2026-13250
5.3 MEDIUM

The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin …

Jul 11, 2026
CVE-2026-13116
4.3 MEDIUM

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Jul 11, 2026
CVE-2026-12141
4.9 MEDIUM

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in …

Jul 11, 2026
CVE-2025-13968
6.4 MEDIUM

The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up …

Jul 11, 2026
CVE-2026-8678
4.3 MEDIUM

The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. This is due to the plugin not …

Jul 11, 2026
CVE-2026-7544
4.3 MEDIUM

The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This …

Jul 11, 2026
CVE-2026-5743
6.4 MEDIUM

The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and including, …

Jul 11, 2026
CVE-2026-3367
4.4 MEDIUM

The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and …

Jul 11, 2026
CVE-2026-15338
7.5 HIGH

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the …

Jul 11, 2026
CVE-2026-15073
6.5 MEDIUM

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions …

Jul 11, 2026
CVE-2026-15072
6.5 MEDIUM

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions …

Jul 11, 2026
CVE-2026-13353
8.8 HIGH

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in …

Jul 11, 2026
CVE-2026-13262
6.5 MEDIUM

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val' parameter …

Jul 11, 2026
CVE-2026-13114
7.2 HIGH

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info …

Jul 11, 2026
CVE-2026-12426
5.3 MEDIUM

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Jul 11, 2026
CVE-2026-10628
4.3 MEDIUM

The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.10.0. This is due …

Jul 11, 2026
CVE-2026-13756
8.8 HIGH

The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing …

Jul 11, 2026
CVE-2026-11426
6.5 MEDIUM

The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to the …

Jul 11, 2026
CVE-2026-55175
7.5 HIGH

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations …

Jul 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.