CVE Vulnerability Database
Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15324 | MEDIUM | 4.4 | 0.2% | Jul 16, 2026 | The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to St... |
| CVE-2026-15106 | MEDIUM | 5.3 | — | Jul 16, 2026 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio... |
| CVE-2026-15103 | HIGH | 8.8 | 0.3% | Jul 16, 2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Pr... |
| CVE-2026-15099 | MEDIUM | 6.4 | — | Jul 16, 2026 | The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute ... |
| CVE-2026-15022 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Sto... |
| CVE-2026-15021 | MEDIUM | 6.4 | 0.2% | Jul 16, 2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all v... |
| CVE-2026-15008 | HIGH | 8.1 | 0.6% | Jul 16, 2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera... |
| CVE-2026-15005 | HIGH | 8.8 | — | Jul 16, 2026 | The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2026-13767 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, an... |
| CVE-2026-13755 | MEDIUM | 6.4 | — | Jul 16, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_... |
| CVE-2026-13754 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' param... |
| CVE-2026-13741 | HIGH | 8.8 | 0.2% | Jul 16, 2026 | The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all v... |
| CVE-2026-15925 | CRITICAL | 9.2 | 0.2% | Jul 16, 2026 | Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed... |
| CVE-2026-12979 | MEDIUM | 5.5 | — | Jul 16, 2026 | The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a t... |
| CVE-2026-12978 | HIGH | 7.1 | — | Jul 16, 2026 | The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the ... |
| CVE-2026-12907 | LOW | 2.7 | 0.1% | Jul 16, 2026 | The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions,... |
| CVE-2026-12906 | LOW | 2.7 | 0.1% | Jul 16, 2026 | The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a r... |
| CVE-2026-12869 | MEDIUM | 6.1 | — | Jul 16, 2026 | The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for ... |
| CVE-2026-12684 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or non... |
| CVE-2026-12585 | HIGH | 8.1 | 0.1% | Jul 16, 2026 | The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recover... |
| CVE-2026-12525 | HIGH | 8.8 | 0.1% | Jul 16, 2026 | The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving cus... |
| CVE-2026-12510 | MEDIUM | 5.9 | 0.1% | Jul 16, 2026 | The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a c... |
| CVE-2026-12492 | CRITICAL | 9.8 | 0.1% | Jul 16, 2026 | The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actu... |
| CVE-2026-12395 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a ... |
| CVE-2026-11866 | MEDIUM | 5.4 | 0.1% | Jul 16, 2026 | The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing a... |
