CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15324MEDIUM4.4The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to St...
CVE-2026-15106MEDIUM5.3The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio...
CVE-2026-15103HIGH8.8The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Pr...
CVE-2026-15099MEDIUM6.4The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute ...
CVE-2026-15022MEDIUM6.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Sto...
CVE-2026-15021MEDIUM6.4The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all v...
CVE-2026-15008HIGH8.1The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera...
CVE-2026-15005HIGH8.8The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2026-13767MEDIUM6.5The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, an...
CVE-2026-13755MEDIUM6.4The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_...
CVE-2026-13754MEDIUM6.5The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' param...
CVE-2026-13741HIGH8.8The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all v...
CVE-2026-15925CRITICAL9.2Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed...
CVE-2026-12979MEDIUM5.5The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a t...
CVE-2026-12978HIGH7.1The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the ...
CVE-2026-12907LOW2.7The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions,...
CVE-2026-12906LOW2.7The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a r...
CVE-2026-12869MEDIUM6.1The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for ...
CVE-2026-12684MEDIUM6.5The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or non...
CVE-2026-12585HIGH8.1The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recover...
CVE-2026-12525HIGH8.8The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving cus...
CVE-2026-12510MEDIUM5.9The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a c...
CVE-2026-12492CRITICAL9.8The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actu...
CVE-2026-12395MEDIUM6.5The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a ...
CVE-2026-11866MEDIUM5.4The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing a...