CVE Vulnerability Database
Search and browse 389,984 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11901 | MEDIUM | 5.3 | 0.2% | Jul 11, 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all version... |
| CVE-2026-11898 | MEDIUM | 4.4 | 0.2% | Jul 11, 2026 | The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions... |
| CVE-2026-11591 | MEDIUM | 4.4 | 0.3% | Jul 11, 2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a... |
| CVE-2026-10865 | MEDIUM | 5.3 | 0.4% | Jul 11, 2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2026-10041 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in al... |
| CVE-2025-6784 | HIGH | 8.8 | 0.5% | Jul 11, 2026 | The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 ... |
| CVE-2025-5017 | MEDIUM | 4.9 | 0.3% | Jul 11, 2026 | The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’... |
| CVE-2026-7655 | HIGH | 8.1 | 0.3% | Jul 11, 2026 | The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and incl... |
| CVE-2026-13378 | HIGH | 7.2 | 0.3% | Jul 11, 2026 | The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contac... |
| CVE-2026-9738 | MEDIUM | 4.4 | 0.2% | Jul 11, 2026 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conten... |
| CVE-2026-7620 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl... |
| CVE-2026-7559 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized acc... |
| CVE-2026-6804 | MEDIUM | 5.3 | 0.4% | Jul 11, 2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions ... |
| CVE-2026-6803 | MEDIUM | 5.3 | 0.3% | Jul 11, 2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions... |
| CVE-2026-3576 | HIGH | 7.2 | 0.4% | Jul 11, 2026 | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local ... |
| CVE-2026-3552 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missi... |
| CVE-2026-2354 | HIGH | 8.8 | 0.6% | Jul 11, 2026 | The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validatio... |
| CVE-2026-1832 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cac... |
| CVE-2026-15335 | HIGH | 7.5 | 0.5% | Jul 11, 2026 | The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in ... |
| CVE-2026-15097 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module ... |
| CVE-2026-15096 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field... |
| CVE-2026-14262 | HIGH | 8.8 | 0.4% | Jul 11, 2026 | The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Byp... |
| CVE-2026-13250 | MEDIUM | 5.3 | 0.3% | Jul 11, 2026 | The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3.... |
| CVE-2026-13116 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference ... |
| CVE-2026-12141 | MEDIUM | 4.9 | 0.2% | Jul 11, 2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored C... |
