Tag
Unauthenticated Remote Code Execution in Pix for WooCommerce
1 rule 2 TTPs 1 CVEA critical vulnerability (CVE-2026-3891) in the Pix for WooCommerce WordPress plugin allows unauthenticated attackers to upload and execute arbitrary PHP files via vulnerable AJAX handlers.
Critical Unauthenticated RCE in Realtyna WPL Real Estate Plugin
1 rule 2 TTPs 1 CVE 1 IOCA critical unauthenticated remote code execution vulnerability, CVE-2026-13714, in Realtyna WPL Real Estate and Organic IDX plugins allows attackers to upload arbitrary PHP shells via the I/O API.
Arbitrary File Read Vulnerability in CubeWP Framework
2 TTPs 1 CVEAn unauthenticated directory traversal vulnerability in the CubeWP Framework plugin allows attackers to read arbitrary files by leveraging exposed AJAX nonces.
Privilege Escalation in Pronamic Pay WordPress Plugin
1 TTP 1 CVEThe Pronamic Pay plugin for WordPress is vulnerable to privilege escalation via the unvalidated update of user roles in the Gravity Forms integration.
Remote Code Execution in Kali Forms WordPress Plugin
1 rule 2 TTPs 1 CVEUnauthenticated attackers can achieve remote code execution in Kali Forms versions up to 2.4.20 by exploiting insufficient validation of the thisPermalink field within the _save_data function.
Arbitrary File Deletion in Nex Forms Plugin for WordPress
1 TTP 1 CVEThe Nex Forms - Ultimate Form Builder - Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal, allowing authenticated attackers to delete critical system files.
Privilege Escalation in Subscriptions for WooCommerce Plugin
1 TTP 1 CVEThe Subscriptions for WooCommerce plugin for WordPress is susceptible to privilege escalation allowing authenticated users with Contributor access to promote themselves to Administrator via insecure meta box handling.
Unauthenticated Remote Code Execution in Realtyna Organic IDX and WPL Real Estate WordPress Plugins
1 rule 1 CVE 1 IOCThe Realtyna Organic IDX and WPL Real Estate plugins contain an arbitrary file upload vulnerability (CVE-2026-14483) allowing unauthenticated remote code execution via static, default API credentials.
Authorization Bypass in Subscriptions for WooCommerce Plugin
1 rule 2 TTPs 1 CVEAn authorization flaw in the Subscriptions for WooCommerce WordPress plugin allows authenticated users with shop manager privileges to remotely install and activate arbitrary plugins.
BuddyPress Insecure Deserialization Vulnerability
1 TTPAn insecure deserialization vulnerability in the BuddyPress WordPress plugin allows authenticated attackers to inject arbitrary PHP objects, potentially leading to remote code execution.
Critical Arbitrary File Upload in WordPress Extra Checkout Options Plugin Leads to RCE (CVE-2026-14270)
2 rules 4 TTPs 1 CVEA critical arbitrary file upload vulnerability (CVE-2026-14270) in the Extra Checkout Options plugin for WordPress, affecting versions up to and including 2.3.2, allows low-privileged authenticated users to modify upload allowlists and upload malicious PHP files via an AJAX action, ultimately achieving remote code execution on the server.
Fluent Forms WordPress Plugin Stored Cross-Site Scripting Vulnerability (CVE-2026-16655)
2 TTPs 1 CVEAn unauthenticated attacker can exploit a Stored Cross-Site Scripting vulnerability (CVE-2026-16655) in the Fluent Forms WordPress plugin, versions up to and including 6.2.7, via insufficient input sanitization of the Name Field Nested `password` Member, allowing injection of arbitrary web scripts that execute in a user's browser upon page access.
CVE-2026-16597 - GTM4WP WordPress Plugin Vulnerable to Stored XSS via WooCommerce Billing Fields
1 rule 1 TTP 1 CVEThe GTM4WP (Google Tag Manager) plugin for WordPress, in versions up to and including 1.22.3, is vulnerable to stored cross-site scripting (XSS) via CVE-2026-16597, allowing unauthenticated attackers to inject arbitrary web scripts through WooCommerce billing fields during a guest checkout, which execute when a user accesses the compromised page.
Remote Code Execution in Cost Calculator Builder PRO WordPress Plugin
1 rule 2 TTPs 1 CVEThe Cost Calculator Builder PRO plugin for WordPress, versions up to and including 4.0.3, is vulnerable to unauthenticated Remote Code Execution (RCE) via CVE-2026-14900 due to insufficient sanitization of the `orderDetails[*].originalValue` field, allowing arbitrary code injection into a `PHP eval()` call that can be exploited by unauthenticated attackers.
Meta Box AIO Plugin Vulnerable to Unauthenticated Post Deletion via CVE-2026-14488
1 rule 1 TTP 1 CVEUnauthenticated attackers can exploit a Missing Authorization vulnerability (CVE-2026-14488) in the MB Frontend Submission extension of the Meta Box AIO plugin for WordPress, affecting versions up to 3.8.0, to delete arbitrary posts and pages by injecting a crafted post ID via a GET parameter.
CVE-2025-10656: WordPress Spreadsheet Price Changer Plugin Missing Authorization Vulnerability
3 TTPs 1 CVECVE-2025-10656 describes a Missing Authorization vulnerability in the Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light plugin for WordPress, affecting all versions up to and including 2.4.37, which allows unauthenticated attackers to create new administrator accounts, leading to privilege escalation and potential full control over affected WordPress sites.
WordPress Database for CF7 Plugin Stored Cross-Site Scripting (CVE-2026-13425)
1 rule 2 TTPs 1 CVEThe Database for CF7 plugin for WordPress is vulnerable to stored Cross-Site Scripting (XSS) via Array Form Field Values, allowing unauthenticated attackers to inject arbitrary web scripts by sending specially crafted array-structured input to the Contact Form 7 REST API endpoint /wp-json/contact-form-7/v1/contact-forms/{id}/feedback, which are insufficiently sanitized and executed when a user accesses an affected page.
Authentication Bypass in Advanced Responsive Video Embedder WordPress Plugin
1 rule 3 TTPs 1 CVEA critical authentication bypass vulnerability, CVE-2026-18072, affects version 10.8.7 of the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress, allowing unauthenticated attackers to gain full administrative control by supplying a hardcoded token via the `_wplogin` or `_wpm` URL parameter.
Easy Digital Downloads Plugin Arbitrary File Upload Leads to RCE (CVE-2026-12476)
1 rule 3 TTPs 1 CVEThe Easy Digital Downloads plugin for WordPress versions up to and including 3.6.9 is vulnerable to Arbitrary File Upload (CVE-2026-12476) due to insufficient file type validation, allowing authenticated attackers with Shop Manager-level access or higher to upload arbitrary files which can lead to remote code execution.
WordPress Wholesale for WooCommerce Plugin Privilege Escalation (CVE-2026-12144)
1 TTP 1 CVEThe Wholesale for WooCommerce plugin for WordPress is vulnerable to privilege escalation due to insufficient validation and capability checks in `save_requests_meta()` function, allowing authenticated attackers with author-level access or higher to escalate their privileges to administrator by supplying 'administrator' as the `user_role_set` value in a crafted request.
WP Password Policy Plugin Privilege Escalation via Crafted POST Request (CVE-2026-15992)
1 rule 1 TTP 1 CVEThe WP Password Policy plugin for WordPress, in versions up to and including 3.7.1, is vulnerable to privilege escalation, allowing authenticated attackers with subscriber-level access to escalate their privileges to Administrator by sending a crafted POST request to the password-reset form endpoint, leveraging missing authorization checks and nonce verification.
WordPress Coding Standards Contains an Arbitrary Code Execution Vulnerability
1 TTPWordPress Coding Standards (WordPressCS) versions before 3.4.1 are vulnerable to arbitrary code execution due to a flaw in the `WordPress.WP.EnqueuedResourceParameters` sniff, allowing an attacker to execute arbitrary commands on the scanning host by crafting a malicious `$ver` argument, posing a risk for users running PHPCS with specific rulesets in CI pipelines or developer environments.
CVE-2026-15025: Missing Authorization in Uncanny Automator WordPress Plugin
1 rule 1 TTP 1 CVEA Missing Authorization vulnerability, CVE-2026-15025, in the Uncanny Automator WordPress plugin versions up to and including 7.3.2, allows authenticated attackers with Subscriber-level access or higher to enumerate sensitive data from integrated Google Contacts and Mautic services, potentially consuming third-party API quotas.
CVE-2026-13440: Stored Cross-Site Scripting in StoreGrowth WooCommerce Plugin
3 TTPs 1 CVEA high-severity Stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-13440, exists in the StoreGrowth: Smart Sales Booster for WooCommerce WordPress plugin (versions up to and including 2.1.0) due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'message_popup' parameter that execute when a user accesses an affected page, facilitated by an exposed nonce.
Generic SQL Injection Vulnerability in WordPress Web Directory Free Plugin (CVE-2026-14785)
1 rule 2 TTPs 1 CVEThe Web Directory Free plugin for WordPress, in all versions up to and including 1.7.13, is vulnerable to generic SQL Injection through the 'levels' parameter. This flaw, caused by insufficient input escaping and lack of query preparation, enables unauthenticated attackers to append arbitrary SQL queries to existing ones, allowing them to extract sensitive information directly from the database.
Privilege Escalation in Eazy Plugin Manager for WordPress (CVE-2026-14328)
2 rules 1 TTP 1 CVEThe Eazy Plugin Manager - Powerful Plugin Management Solution for WordPress plugin for WordPress (versions up to and including 4.4.1) is vulnerable to privilege escalation (CVE-2026-14328), allowing authenticated attackers with Subscriber-level access to read sensitive WordPress options, compute an authentication key, and obtain Administrator authentication cookies, leading to full site takeover if the plugin's remote connection feature is configured.
WordPress PickPlugins Question Answer Plugin SQL Injection Vulnerability (CVE-2026-10207)
1 rule 2 TTPs 1 CVEAn unauthenticated SQL injection vulnerability, tracked as CVE-2026-10207, exists in the PickPlugins Question Answer plugin for WordPress versions up to and including 1.2.73, allowing attackers to extract sensitive database information due to insufficient input sanitization of the 'id' GET parameter and improper SQL query construction.
CVE-2026-14516 - Bookly WordPress Plugin Time-Based SQL Injection
1 rule 2 TTPs 1 CVEUnauthenticated attackers can exploit a time-based SQL Injection vulnerability (CVE-2026-14516) in the Bookly WordPress plugin, affecting versions up to and including 27.5, via the 'staff_ids' parameter, chaining requests to `bookly_get_form_id` and `bookly_render_time` to extract sensitive database information due to insufficient input escaping and lack of CSRF protection.
TrueBooker WordPress Plugin SQL Injection Vulnerability (CVE-2026-13161)
1 rule 2 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-13161, a generic SQL Injection vulnerability in the TrueBooker - Appointment Booking and Scheduler System plugin for WordPress affecting versions up to and including 1.2.2, by manipulating the 'alldata[truebooker_user]' parameter in POST requests, allowing the extraction of sensitive database information.
WordPress Premium Packages Plugin SQL Injection Vulnerability (CVE-2026-12800)
1 rule 3 TTPs 1 CVEThe Premium Packages - Sell Digital Products Securely plugin for WordPress, in versions up to and including 6.2.0, is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint, allowing unauthenticated attackers to append additional SQL queries to extract sensitive database information.
CVE-2026-12741: Unauthenticated SQL Injection in WP Fast Total Search WordPress Plugin
1 rule 2 TTPs 1 CVEAn SQL injection vulnerability (CVE-2026-12741) exists in the WP Fast Total Search - The Power of Indexed Search plugin for WordPress, affecting all versions up to and including 1.80.280. The flaw, located in the 'form_data[s]' parameter, is due to insufficient input escaping and poor SQL query preparation, allowing unauthenticated attackers to inject malicious SQL queries and extract sensitive information from the underlying database.
Authentication Bypass in WordPress SMS Alert Plugin Leads to Account Takeover (CVE-2026-15014)
1 rule 2 TTPs 1 CVEAn authentication bypass vulnerability (CVE-2026-15014) in the 'SMS Alert - SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery' WordPress plugin allows unauthenticated attackers to achieve account takeover by exploiting a flaw in the `processRegistration()` function's OTP verification, enabling authentication as any existing WordPress user with a known phone number.
Arbitrary File Deletion Vulnerability in WordPress Better Messages Plugin
1 rule 2 TTPs 1 CVEA path traversal vulnerability, CVE-2026-16585, in the Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress allows authenticated administrators to delete arbitrary files on the server by bypassing file path validation, potentially leading to remote code execution.
The Demi WordPress Plugin Vulnerable to Arbitrary Directory Deletion (CVE-2026-14490)
2 TTPs 1 CVEUnauthenticated attackers can exploit CVE-2026-14490 in The Demi - One Click Demo Import, WP Backup & Site Migration WordPress plugin (versions up to and including 0.0.7) to achieve arbitrary directory deletion by retrieving a publicly exposed HMAC signing key and forging valid requests to a vulnerable AJAX handler.
Fluent Forms Pro Add On Pack Vulnerable to PHP Object Injection (CVE-2026-15962)
3 TTPs 1 CVEAn authenticated attacker with Subscriber-level access or higher can exploit a PHP Object Injection vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress, affecting versions up to and including 6.2.6. This deserialization of untrusted input, when combined with a POP chain, allows attackers to change user passwords and potentially achieve administrator account takeover. Exploitation is contingent on user update integration being enabled and a user meta field being mapped.
WPForms Pro Plugin Arbitrary File Upload Vulnerability Leading to RCE
1 rule 2 TTPs 1 IOCThe WPForms Pro plugin for WordPress, in versions up to and including 1.10.1.1, is vulnerable to arbitrary file upload via the ajax_chunk_upload_finalize function, allowing unauthenticated attackers to upload executable files due to improper file type validation occurring after file contents are written to disk, which can lead to remote code execution on the affected server.
CVE-2026-8789: Easy Appointments WordPress Plugin Data Modification Vulnerability
1 rule 1 TTP 1 CVEThe Easy Appointments plugin for WordPress, in versions up to and including 3.12.27, is vulnerable to unauthorized data modification due to a missing capability check and nonce verification on the `ea_delete_multiple_connections` AJAX action, allowing authenticated attackers with Contributor-level access or higher to delete arbitrary connection records and disrupt core booking functionality.
VikBooking Hotel Booking Engine & PMS Plugin Vulnerable to Stored Cross-Site Scripting (CVE-2026-15401)
1 rule 2 TTPs 1 CVEThe VikBooking Hotel Booking Engine & PMS plugin for WordPress versions up to and including 1.8.13 is vulnerable to Stored Cross-Site Scripting (XSS) via the 'vbfX' parameter, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an infected page.
Wpify Woo Plugin Privilege Escalation Vulnerability (CVE-2026-12736)
1 rule 2 TTPs 1 CVEA privilege escalation vulnerability (CVE-2026-12736) in the Wpify Woo plugin for WordPress, affecting versions up to and including 5.4.16, allows authenticated attackers with 'Shop Manager' capabilities or higher to gain Administrator privileges by exploiting a REST route that overwrites arbitrary WordPress options.
WordPress SAML Single Sign On Plugin Authentication Bypass (CVE-2026-15981)
2 TTPs 1 CVE 2 IOCsA critical authentication bypass vulnerability, CVE-2026-15981, affects the SAML Single Sign On - SSO Login plugin for WordPress (versions up to and including 5.4.4), allowing unauthenticated attackers to log in as any existing user, including administrators, by crafting a malformed SAMLResponse that misleads the plugin's signature validation logic.
CVE-2026-15212: WordPress WPO365 Login Plugin Cross-Site Request Forgery Vulnerability
1 rule 4 TTPs 1 CVEA Cross-Site Request Forgery (CSRF) vulnerability in the WPO365 | Login plugin for WordPress, affecting versions up to and including 43.2, allows unauthenticated attackers to overwrite arbitrary plugin options. This is due to a misconfiguration where the nonce check is effectively disabled. By tricking a site administrator into clicking a malicious link, an attacker can manipulate settings such as enabling the SCIM REST endpoint, planting a SCIM secret token, and setting the default user role for new registrations to 'administrator', potentially leading to full site compromise and unauthorized administrative access.
WordPress MDJM Event Management Plugin Privilege Escalation (CVE-2026-15017)
2 TTPs 1 CVEAn unauthenticated privilege escalation vulnerability (CVE-2026-15017) in the MDJM Event Management plugin for WordPress, affecting all versions up to 1.7.8.4, allows attackers to grant arbitrary MDJM capabilities to any registered WordPress role due to missing capability checks and nonce verification, ultimately enabling a low-privilege user to escalate to Administrator.
MountDev AI MCP Connector WordPress Plugin Vulnerability Allows Unauthenticated Admin Access (CVE-2026-15015)
1 rule 2 TTPs 1 CVEAn authorization bypass vulnerability, CVE-2026-15015, in all versions up to 1.6.1 of the MountDev AI MCP Connector for WordPress plugin allows unauthenticated attackers to obtain an administrator-bound OAuth Bearer token by exploiting publicly accessible client registration and an unprotected authorization endpoint, granting full administrator-equivalent access to the plugin's tool surface and WordPress content.
Critical Code Injection Vulnerability in WordPress Customer Support Ticket System & Helpdesk Plugin (CVE-2026-15011)
1 TTP 1 CVEA critical code injection vulnerability, CVE-2026-15011, affects the Customer Support Ticket System & Helpdesk plugin for WordPress versions up to and including 6.0.5, allowing unauthenticated attackers to invoke arbitrary parameterless PHP functions via the 'path' parameter, potentially disrupting site functionality or exposing sensitive information without prior authentication.
GoDAM WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-14282)
1 rule 2 TTPs 1 CVEAn arbitrary file upload vulnerability exists in the GoDAM WordPress plugin versions up to and including 1.12.2 due to insufficient file type validation in the `save_video_file()` function, allowing unauthenticated attackers to upload arbitrary files to the server and potentially achieve remote code execution.
CVE-2026-9713: Lumise Product Designer for WooCommerce Plugin SQL Injection
1 rule 2 TTPs 1 CVEThe Lumise Product Designer for WooCommerce plugin for WordPress, in versions up to and including 2.1.1, is vulnerable to SQL Injection via the 'id' and 'table' parameters within an uploaded cart JSON file processed by the checkout AJAX action, allowing unauthenticated attackers to extract sensitive database information.
ARforms WordPress Plugin Vulnerable to Stored Cross-Site Scripting via 'password' Field (CVE-2026-12421)
2 TTPs 1 CVEAn insufficient input sanitization and output escaping vulnerability (CVE-2026-12421) in the ARforms plugin for WordPress, affecting versions up to and including 7.2.1, allows unauthenticated attackers to inject arbitrary web scripts via the 'password' field, leading to Stored Cross-Site Scripting (XSS) when a user accesses an injected page.
SUMO Reward Points WordPress Plugin Vulnerable to Unauthenticated Stored XSS via REST API (CVE-2026-7534)
1 rule 2 TTPs 1 CVEThe SUMO Reward Points plugin for WordPress, versions up to and including 32.7.0, is vulnerable to CVE-2026-7534, an Unauthenticated Stored Cross-Site Scripting flaw that allows attackers to inject arbitrary web scripts into the reward points log via the `/wp-json/wc-srp/v1/earning` REST API endpoint, executing when an administrator accesses specific admin pages.
FormCraft WordPress Plugin Stored XSS Vulnerability
1 rule 2 TTPs 1 CVEThe FormCraft plugin for WordPress, specifically versions up to and including 3.9.14, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-7232) that allows unauthenticated attackers to inject arbitrary web scripts into web pages via manipulated form parameters due to insufficient input sanitization and output escaping, leading to script execution in users' browsers when accessing affected pages.
WP Foodbakery Plugin Arbitrary File Deletion Vulnerability
1 rule 2 TTPs 1 CVEThe WP Foodbakery plugin for WordPress, specifically versions up to and including 4.9, is vulnerable to arbitrary file deletion (CVE-2026-15802) due to insufficient file path validation, allowing authenticated attackers with subscriber-level access to delete critical server files, potentially leading to remote code execution.
Unauthenticated Input Validation Bypass in Ninja Forms WordPress Plugin (CVE-2026-65052)
1 TTP 1 CVEAn improper input validation vulnerability, identified as CVE-2026-65052, in Ninja Forms WordPress plugin versions 3.14.8 and prior allows unauthenticated attackers to tamper with form submission payloads to the ajax submit endpoint, injecting arbitrary numeric values into form calculations and payment totals, thereby bypassing admin-configured pricing logic and potentially reducing payment amounts to zero.
Ninja Forms Plugin Vulnerability Allows Network-Wide Data Deletion in WordPress Multisite
1 rule 2 TTPs 1 CVEA critical privilege escalation vulnerability, CVE-2026-65049, in the Ninja Forms plugin (version 3.14.8 and prior) for WordPress Multisite allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting an incorrect authorization check combined with unsafe multisite migration defaults, leading to severe data loss.
Critical Unauthenticated Stored XSS in Ninja Forms WordPress Plugin (CVE-2026-65048)
1 rule 6 TTPs 1 CVEA critical unauthenticated stored cross-site scripting (XSS) vulnerability (CVE-2026-65048) in the Ninja Forms plugin for WordPress allows attackers to inject malicious script payloads via crafted form submissions, leading to session-cookie theft, administrator account creation, and arbitrary content modification when an administrator views the submission.
MapSVG WordPress Plugin Vulnerability Allows Arbitrary File Uploads (CVE-2026-1771)
1 rule 3 TTPs 1 CVEAn authenticated attacker with Administrator-level access can exploit CVE-2026-1771 in the MapSVG WordPress plugin, affecting versions up to 8.14.0, due to missing file type validation, enabling arbitrary file uploads and potentially leading to remote code execution on the server.
WordPress Easy Form Builder Plugin Vulnerable to Unauthenticated Administrator Privilege Escalation (CVE-2026-13439)
1 rule 2 TTPs 1 CVEAn unauthenticated privilege escalation vulnerability exists in the Easy Form Builder by WhiteStudio plugin for WordPress, affecting versions up to and including 4.0.11, allowing attackers to exploit a flaw in the password recovery process by using a publicly visible session identifier ('sid') as a reset token, combined with a publicly accessible nonce refresh endpoint, to set an arbitrary new password for any WordPress user, including administrators, to gain full control.
PHP File Creation in WordPress Plugin Directory
1 rule 3 TTPs 1 CVE 1 IOCAttackers commonly establish persistence on compromised Linux WordPress web servers by creating malicious PHP files, often web shells, within the WordPress plugin directory, enabling remote access and command execution following initial compromise of a public-facing application.
WordPress: Multiple Vulnerabilities Enable Code Execution
1 TTPA remote, unauthenticated attacker can exploit multiple, unspecified vulnerabilities in WordPress to execute arbitrary program code, potentially leading to a complete compromise of the web server hosting the instance.
CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core
2 TTPs 15 CVEs 8 IOCsCVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.
Privilege Escalation Vulnerability in Aimogen Pro WordPress Plugin
2 TTPs 1 CVEA critical privilege escalation vulnerability, CVE-2026-15982, exists in the Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit WordPress plugin, affecting versions up to and including 2.8.4, allowing unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists, execute arbitrary PHP functions, and create administrator accounts, leading to full compromise of the WordPress site.
Sensitive Information Exposure in LearnPress WordPress Plugin (CVE-2026-13765)
1 rule 2 TTPs 1 CVEAn unauthenticated sensitive information exposure vulnerability (CVE-2026-13765) in the LearnPress - WordPress LMS Plugin for Create and Sell Online Courses, versions up to 4.4.1, allows attackers to extract quiz answers, options, explanations, and question content, including for paid courses.
Arbitrary File Upload Vulnerability in ProfilePress WordPress Plugin (CVE-2026-13352)
3 TTPs 1 CVEAn arbitrary file upload vulnerability, CVE-2026-13352, affects the ProfilePress plugin for WordPress up to version 4.16.18, allowing authenticated attackers with author-level privileges or higher to upload executable files, which can lead to remote code execution.
Kali Forms WordPress Plugin Vulnerable to Stored Cross-Site Scripting via digitalSignature Field
1 rule 6 TTPs 1 CVEThe Kali Forms - Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'digitalSignature' field in versions up to and including 2.4.18, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an affected page.
Bricksforge WordPress Plugin Privilege Escalation Vulnerability (CVE-2026-14956)
1 TTP 1 CVEThe Bricksforge plugin for WordPress, in versions up to and including 3.1.8.6, contains a critical privilege escalation vulnerability, CVE-2026-14956, allowing unauthenticated attackers to register new administrator accounts by manipulating the 'fieldIds' parameter in Pro Forms registration actions, leading to full compromise of the WordPress site.
Stored Cross-Site Scripting Vulnerability in Breakdance WordPress Plugin
1 rule 2 TTPs 1 CVEThe Breakdance plugin for WordPress, in versions up to and including 2.7.1, is susceptible to CVE-2026-7543, a Stored Cross-Site Scripting (XSS) vulnerability via the 'fields' parameter, enabling unauthenticated attackers to inject arbitrary web scripts that execute when users access affected pages, potentially leading to session hijacking, data theft, or defacement.
WPFunnels Plugin Privilege Escalation via Arbitrary Option Update
1 rule 1 TTP 1 CVEAuthenticated attackers with the `wpf_manage_funnels` capability can exploit CVE-2026-15103, a privilege escalation vulnerability in the `update_settings()` REST callback of the WPFunnels - Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress (versions up to and including 3.12.8), allowing them to gain full site administrator access by injecting a crafted role definition into the `wp_user_roles` option.
Uncanny Automator WordPress Plugin Vulnerable to Arbitrary File Deletion (CVE-2026-15008)
2 TTPs 1 CVEA critical arbitrary file deletion vulnerability, CVE-2026-15008, exists in The Uncanny Automator plugin for WordPress, versions up to and including 7.3.1.4, due to insufficient file path validation in the `fr_token` function, allowing unauthenticated attackers to delete arbitrary files on the server and potentially achieve remote code execution (RCE) by targeting critical files like `wp-config.php`, provided a Forminator form is linked to an 'Everyone' configured Uncanny Automator recipe, enabling the submission of a malicious serialized payload that leverages a gadget chain within the plugin's `Action_Helpers_Email __destruct()` method.
CVE-2026-15005 - WordPress Loco Translate Plugin Cross-Site Request Forgery Vulnerability
1 rule 2 TTPs 1 CVEA Cross-Site Request Forgery vulnerability (CVE-2026-15005) in the WordPress Loco Translate plugin, affecting all versions up to 2.8.5, allows unauthenticated attackers to achieve remote code execution by tricking an administrator into clicking a malicious link, leading to arbitrary PHP code execution via `php://filter` stream wrapper abuse.
WordPress Digits Plugin Privilege Escalation via Missing Authorization
1 rule 1 TTP 1 CVEThe Digits: WordPress Mobile Number Signup and Login plugin is vulnerable to privilege escalation, allowing authenticated attackers with Subscriber-level access to elevate privileges to Administrator by submitting a forged `digits_reg_userrole` value during profile update, impacting WordPress sites configured with the built-in DIGITS User Role field.
RPB Chessboard WordPress Plugin Vulnerable to Stored Cross-Site Scripting
1 TTP 1 CVEThe RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within its comment content functionality, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user views the affected page, bypassing WordPress's default kses sanitization.
Authentication Bypass in miniOrange SAML SSO Login Plugin for WordPress (CVE-2026-15013)
3 TTPsA critical authentication bypass vulnerability (CVE-2026-15013) exists in the SAML Single Sign On - SSO Login plugin for WordPress, affecting all versions up to and including 5.4.3, enabling unauthenticated attackers to forge SAML assertions and achieve full administrator-level account takeover due to signature algorithm confusion.
SQL Injection Vulnerability in WordPress WooCommerce Advanced Product Search Plugin (CVE-2026-12753)
1 rule 2 TTPs 1 CVEA SQL Injection vulnerability, CVE-2026-12753, has been identified in the Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress, affecting all versions up to and including 1.4.4. The flaw, caused by insufficient input sanitization of the 's' and 'match' parameters and inadequate SQL query preparation, allows unauthenticated attackers to append arbitrary SQL queries. This enables them to extract sensitive information directly from the database.
Gravity Forms Directory Traversal Vulnerability (CVE-2026-12997)
1 rule 2 TTPs 1 CVEUnauthenticated attackers can exploit a Directory Traversal vulnerability (CVE-2026-12997) in the Gravity Forms plugin for WordPress, affecting all versions up to and including 2.10.4, to read arbitrary files on the server and receive their contents as an email attachment, potentially exfiltrating sensitive information.
Critical Vulnerability in Podlove Podcast Publisher Plugin Allows Unauthenticated File Uploads Leading to RCE
1 rule 3 TTPs 1 CVE 4 IOCsA critical vulnerability, CVE-2026-13001, in the Podlove Podcast Publisher plugin for WordPress, impacting versions up to and including 4.5.1, allows unauthenticated attackers to upload arbitrary files due to missing file type validation, potentially leading to remote code execution on the server.
Vulnerability in Genolve WordPress Plugin Allows Privilege Escalation
1 rule 1 TTP 1 CVEA vulnerability in the Genolve AI image AI video generation plugin for WordPress, affecting versions up to and including 5.0.5, allows authenticated attackers with Contributor-level access to achieve privilege escalation due to a missing capability check in the `genolve_setOpt()` function, enabling them to modify arbitrary WordPress options such as enabling user registration and setting the default role to administrator.
Directory Traversal in W3 Total Cache WordPress Plugin (CVE-2026-9282)
1 rule 3 TTPs 1 CVEAn unauthenticated directory traversal vulnerability (CVE-2026-9282) in all versions up to 2.9.4 of the W3 Total Cache plugin for WordPress allows attackers to read arbitrary files by manipulating the minify filename when manual minify mode is enabled.
CVE-2026-6939: Unauthenticated Stored XSS in CorvusPay WooCommerce Payment Gateway for WordPress
1 rule 2 TTPs 1 CVEThe CorvusPay WooCommerce Payment Gateway plugin for WordPress versions up to and including 2.7.4 is vulnerable to Stored Cross-Site Scripting (XSS), tracked as CVE-2026-6939, allowing unauthenticated attackers to inject malicious web scripts via the 'approval_code' parameter to the `/wp-json/corvuspay/success/` REST endpoint, which processes requests without proper signature validation, leading to script execution when a user accesses an affected page.
WP CTA Plugin Vulnerable to Unauthenticated Time-Based Blind SQL Injection (CVE-2026-4661)
1 rule 2 TTPs 1 CVEThe WP CTA - Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in versions up to and including 2.2.2. This vulnerability is due to insufficient escaping of user-supplied column names and lack of preparation in database queries. Unauthenticated attackers can exploit this by injecting arbitrary SQL queries to extract sensitive information, including administrator password hashes, from the database.
Authenticated Account Takeover in Essential Addons for Elementor WordPress Plugin
3 TTPs 1 CVEA vulnerability (CVE-2026-15155) in the Essential Addons for Elementor WordPress plugin, specifically within its Login/Register widget, allows authenticated attackers with Contributor-level access or higher to achieve administrator account takeover by injecting an additional Bcc header into administrator password-reset notification emails.
Remote Code Execution in WordPress Code Engine Plugin via Shortcode (CVE-2025-6784)
1 rule 2 TTPs 1 CVEThe Code Engine plugin for WordPress, in versions up to and including 0.3.5, is vulnerable to Remote Code Execution (RCE) via its 'code-engine' shortcode, allowing authenticated attackers with Contributor-level access or above to execute arbitrary code on the server.
SureCart WordPress Plugin Vulnerable to Account Takeover and Privilege Escalation
2 TTPs 1 CVEThe SureCart plugin for WordPress, in versions up to and including 4.2.3, is vulnerable to privilege escalation through an account takeover, where unauthenticated attackers can exploit a lack of proper identity validation during customer profile synchronization via webhook events to change linked user email addresses, potentially leading to administrator account compromise.
CVE-2026-13378 - Form Vibes WordPress Plugin Vulnerable to Stored Cross-Site Scripting
1 rule 2 TTPs 1 CVE 5 IOCsThe Form Vibes - Database Manager for Forms plugin for WordPress, including all versions up to and including 1.5.2, is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages that execute when a user accesses an injected page.
CVE-2026-3576: Planyo WordPress Plugin Vulnerable to SSRF and LFI
1 rule 2 TTPs 1 CVEThe Planyo Online Reservation System plugin for WordPress, in all versions up to and including 3.0, is vulnerable to Server-Side Request Forgery (SSRF) leading to Local File Inclusion (LFI), allowing an unauthenticated attacker to exploit the `ulap.php` file by supplying a `file://` URL that bypasses the host allowlist, reading arbitrary local files on the server and retrieving their contents in the HTTP response, potentially disclosing sensitive data.
The Swiss Toolkit For WP Plugin Vulnerable to Arbitrary File Upload Leading to RCE (CVE-2026-2354)
1 rule 3 TTPs 1 CVEA critical arbitrary file upload vulnerability (CVE-2026-2354) exists in The Swiss Toolkit For WP plugin for WordPress, affecting all versions up to and including 1.4.6. The flaw, located in the `upload_extension_files()` function, allows authenticated attackers with Author-level access or higher to bypass file type validation due to an improper `strpos()` check, enabling the upload of arbitrary files, including PHP scripts, which can lead to remote code execution on the server if the "Enhanced Multi-Format Image Support" feature is active with at least one configured extension.
WordPress Booking Package Plugin Vulnerable to Unauthenticated SQL Injection
1 TTP 1 CVEThe Booking Package plugin for WordPress is vulnerable to unauthenticated generic SQL Injection via the 'email' form parameter in versions up to and including 1.7.20, allowing attackers to extract sensitive information from the database.
CVE-2026-14262: WordPress Simple JWT Login Plugin Authentication Bypass to Privilege Escalation
1 rule 1 TTP 1 CVEAn authentication bypass vulnerability (CVE-2026-14262) exists in the WordPress Simple JWT Login plugin, affecting all versions up to and including 3.6.6, which allows authenticated attackers with subscriber-level access or higher to escalate privileges to Administrator by injecting crafted identity claims into the `payload` parameter of a JWT token.
Local File Inclusion Vulnerability in LA-Studio Element Kit for Elementor Plugin for WordPress
4 TTPs 1 CVEA Local File Inclusion vulnerability exists in the LA-Studio Element Kit for Elementor plugin for WordPress, affecting all versions up to and including 1.6.1, which allows authenticated attackers with contributor-level access or higher to include and execute arbitrary .php files on the server due to improper path traversal handling and an easily bypassed extension check, leading to PHP code execution, access control bypass, and sensitive data exposure.
Remote Code Execution in WP Ultimate CSV Importer WordPress Plugin
1 rule 2 TTPs 1 CVEThe WP Ultimate CSV Importer - WordPress Import & Export for CSV, XML & Excel plugin for WordPress, versions up to and including 8.0.1, is vulnerable to Remote Code Execution due to missing capability checks on specific AJAX handlers and exposure of the plugin's nonce, allowing authenticated attackers with subscriber-level access to execute arbitrary code on the server.
CVE-2026-13114: Stored Cross-Site Scripting in WordPress Motors - Car Dealership & Classified Listings Plugin
2 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-13114, a Stored Cross-Site Scripting vulnerability in the WordPress Motors - Car Dealership & Classified Listings Plugin versions up to 1.4.112, by injecting arbitrary web scripts into comment content or user biographical information, leading to client-side code execution when a victim views the affected page.
CVE-2026-13756 - Privilege Escalation in WP Grid Builder WordPress Plugin
1 rule 1 TTP 1 CVEAn authenticated attacker with Subscriber-level access or higher can exploit a missing authorization and meta key validation vulnerability in the WP Grid Builder plugin for WordPress (versions up to and including 2.3.3) by sending a crafted nested array payload to the `/wp-json/wpgb/v2/metadata` REST endpoint, which allows them to update their own `wp_capabilities` user meta and effectively escalate their privileges to Administrator level.
miniOrange WordPress Plugin Authentication Bypass via OTP Weakness
4 TTPs 1 CVEAn authentication bypass vulnerability (CVE-2026-12761) in the miniOrange Social Login and Register WordPress plugin, affecting versions up to 7.7.0, allows unauthenticated attackers to trigger an OTP email to an arbitrary admin's address, offline crack the weak OTP from a leaked hash, and gain full administrator access by logging in as the target user.
Arbitrary Post Creation and Stored XSS in Squirrly SEO Plugin for WordPress
1 rule 3 TTPs 1 CVEAn arbitrary post creation and stored cross-site scripting (XSS) vulnerability exists in The SEO Plugin by Squirrly SEO for WordPress, affecting versions up to and including 14.0.0. This flaw, caused by an API token leak and insufficient input sanitization/output escaping, allows unauthenticated attackers to create arbitrary posts. If the Advanced Custom Fields plugin is also installed, attackers can inject arbitrary web scripts into pages that execute when a user accesses an injected page, leading to potential client-side compromise.
WordPress Hide My WP Lite Plugin Vulnerable to Arbitrary File Read (CVE-2026-13347)
1 rule 2 TTPs 1 CVEThe Hide My WP Lite plugin for WordPress, versions up to and including 1.3, is vulnerable to Arbitrary File Read (CVE-2026-13347) due to inadequate validation of user-supplied input in query parameters `he_wrapper_js` and `he_wrapper_css` within the `elementor_assets_filter()` function, allowing unauthenticated attackers to read arbitrary files on the server like `wp-config.php` when the Elementor plugin and 'Hide Elementor' feature are enabled.
CVE-2026-15298: WordPress TelSender Plugin DOM-Based Cross-Site Scripting
1 TTP 1 CVE 8 IOCsThe TelSender plugin for WordPress, versions up to and including 1.14.14, is vulnerable to DOM-Based Cross-Site Scripting (CWE-79), allowing unauthenticated attackers to inject malicious scripts via Telegram chat titles which execute within an administrator's browser upon interacting with the plugin's settings.
CVE-2026-15293 - WP Business Intelligence Lite Plugin Authorization Bypass Leading to Privilege Escalation
2 TTPs 1 CVEThe WP Business Intelligence Lite plugin for WordPress contains an authorization bypass vulnerability (CVE-2026-15293) affecting all versions up to and including 3.2.0, allowing authenticated attackers with Subscriber-level access or higher to modify stored SQL queries which can lead to arbitrary SQL execution and privilege escalation when an administrator views the modified query.
CVE-2026-15291: WordPress Chat Help Plugin Sensitive Information Exposure
1 rule 2 TTPs 1 CVEUnauthenticated attackers can exploit CVE-2026-15291, a vulnerability in the Chat Help - Click to Chat Button & Form WordPress plugin (versions up to and including 3.1.3), due to a lack of authentication and authorization checks on specific REST API endpoints (/wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}), allowing them to extract sensitive user data, including names, email addresses, phone numbers, WhatsApp messages, complete geolocation data, device fingerprinting, and WordPress account credentials for logged-in users who submitted forms.
CVE-2026-15290: Ultimate Member Plugin Blind SQL Injection
1 rule 2 TTPs 2 CVEsThe Ultimate Member plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in all versions up to and including 2.10.1, due to insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
CVE-2026-15288: SureForms WordPress Plugin Payment Manipulation Vulnerability
1 rule 1 TTP 1 CVEThe SureForms - Drag and Drop Form Builder for WordPress plugin (versions up to and including 2.2.1) is vulnerable to improper input validation (CVE-2026-15288), allowing unauthenticated attackers to modify payment amounts in user-controlled POST data when submitting Stripe payment forms, enabling them to purchase products or services at arbitrarily reduced prices.
CVE-2026-15300: Critical SQL Injection in GEO my WP WordPress Plugin
1 rule 2 TTPs 1 CVEA critical SQL Injection vulnerability, identified as CVE-2026-15300, was found in the GEO my WP plugin for WordPress, affecting versions up to and including 4.5.4, allowing attackers to inject SQL payloads through the 'distance', 'lat', and 'lng' parameters, leading to potential data compromise or denial of service.
CVE-2026-15282: WordPress Instant Appointment Plugin Arbitrary File Upload to RCE
1 rule 2 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-15282, an arbitrary file upload vulnerability due to missing file type validation in the `insapp_upload_image_as_attachment` function of the WordPress Instant Appointment plugin up to version 1.2, to upload malicious files and achieve remote code execution on the affected server.
CVE-2026-15070: WordPress Salon Booking Plugin CSRF to RCE
1 rule 3 TTPsThe Salon Booking System - Free Version plugin for WordPress (versions up to and including 10.30.32) is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability stemming from a lack of nonce validation in the setCustomText function, allowing unauthenticated attackers to inject arbitrary PHP code into the web-accessible translate-constants.php file, which can lead to remote code execution (RCE) on the server if an administrator is tricked into clicking a crafted link.
CVE-2026-13430: WordPress Post Export Import with Media Plugin Arbitrary File Upload Leading to RCE
1 rule 2 TTPs 1 CVEA high-severity arbitrary file upload vulnerability, CVE-2026-13430, exists in all versions up to 1.13.1 of the Post Export Import with Media plugin for WordPress, allowing authenticated administrators to upload executable web shells via a trailing-dot filename bypass, leading to remote code execution.
WordPress Super Forms Plugin Arbitrary File Upload (CVE-2026-14894)
1 rule 2 TTPs 1 CVE 1 IOCAn unauthenticated arbitrary file upload vulnerability (CVE-2026-14894) exists in the Super Forms - Drag & Drop Form Builder plugin for WordPress, affecting all versions up to and including 6.3.313, allowing unauthenticated attackers to upload executable files via the `submit_form` AJAX handler, leading to remote code execution after trivial nonce bypass.
CVE-2026-12598: LoginPress Pro WordPress Plugin Authentication Bypass
2 TTPs 1 CVEAn authentication bypass vulnerability (CVE-2026-12598) exists in the LoginPress Pro plugin for WordPress, affecting versions up to and including 6.2.3 within the Spotify Social Login addon, enabling unauthenticated attackers to log in as any existing WordPress user, including administrators, by registering a Spotify account with the target's email.
UsersWP Plugin Arbitrary File Deletion (CVE-2026-13492)
1 rule 3 TTPs 1 CVEThe UsersWP plugin for WordPress contains an Arbitrary File Deletion vulnerability, CVE-2026-13492, in versions up to and including 1.2.65, allowing an authenticated attacker with Subscriber-level access or higher to exploit insufficient validation in file-field values combined with an AJAX handler that lacks proper path canonicalization to delete arbitrary files on the server, including critical files like `wp-config.php`, leading to system impact.
CVE-2026-9253: WordPress E&P Forms Plugin Stored Cross-Site Scripting
2 TTPs 1 CVEAn unauthenticated attacker can inject arbitrary web scripts into WordPress sites running the 'WP Cost Estimation & Payment Forms Builder' plugin version 10.5.97 and earlier by exploiting CVE-2026-9253, a Stored Cross-Site Scripting vulnerability via the 'customerInfos' parameter, leading to script execution in users' browsers and potential session hijacking or data theft.
CVE-2026-4275 - The Divi Torque Lite - Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to CSRF
1 rule 1 TTP 1 CVEThe Divi Torque Lite plugin for WordPress, in versions up to 4.2.3, is vulnerable to Cross-Site Request Forgery (CVE-2026-4275), allowing an unauthenticated attacker to exploit inadequate nonce verification on the /install_plugin and /activate_plugin REST API endpoints to install arbitrary WordPress plugins, potentially leading to remote code execution or further system compromise.
CVE-2026-14372 - The Bit Form WordPress Plugin Arbitrary File Deletion
3 TTPs 1 CVEThe Bit Form WordPress plugin (versions up to 3.1.1) is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with subscriber-level access to delete critical server files like wp-config.php, potentially leading to remote code execution.
EventPrime WordPress Plugin Stored XSS (CVE-2026-13441)
1 rule 2 TTPs 1 CVEA critical stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-13441, exists in all versions up to 4.3.4.2 of the EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress, allowing authenticated attackers with custom-level access (or unauthenticated attackers if 'Guest Submissions' is enabled) to inject malicious web scripts via the new_event_type_background_color parameter that execute whenever a user accesses an affected page, potentially leading to session hijacking, defacement, or further compromise.
CVE-2026-15158: Blocksy Companion Plugin Arbitrary File Upload Leading to RCE
2 TTPs 1 CVEThe Blocksy Companion plugin for WordPress, specifically the premium version (blocksy-companion-pro) with the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions active, is vulnerable to Arbitrary File Upload (CVE-2026-15158). This flaw, present in versions up to and including 2.1.46, arises from improper file type validation within the `save_attachments` function, allowing double-extension files like `shell.woff2.php` to bypass MIME checks, which unauthenticated attackers can exploit to upload executable files, leading to remote code execution.
CVE-2026-8848: Popup Maker WordPress Plugin Authorization Bypass Leading to RCE
1 rule 2 TTPs 1 CVEAn authorization bypass vulnerability, CVE-2026-8848, exists in the Popup Maker WordPress plugin versions up to and including 1.22.0, allowing authenticated attackers with editor-level access or higher to install and activate arbitrary plugins from a controlled URL, which leads to remote code execution, provided a valid Popup Maker Pro license is active and the Pro version is not yet installed.
CVE-2026-15000: WordPress Plugin Stored XSS
1 rule 2 TTPs 1 CVEThe Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization. This vulnerability, affecting versions up to and including 0.9.78.06, allows unauthenticated attackers to inject arbitrary web scripts into pages. These scripts execute when a privileged user (Administrator) performs a Contact Lookup on an email address submitted via a CF7 form, indicating a deferred execution model. Detection engineers should focus on monitoring for unusual script injections in forms and administrator interactions with plugin data.
CVE-2026-14245 - miniOrange OTP WordPress Plugin Authentication Bypass
3 TTPs 1 CVEA critical authentication bypass vulnerability, CVE-2026-14245, exists in the miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress, affecting all versions up to 5.5.1, allowing unauthenticated attackers to obtain a password-reset URL for an arbitrary Administrator account and achieve full account takeover due to a lack of server-side OTP verification and reliance on a publicly exposed `form_nonce`.
Divi Form Builder Missing Authorization Vulnerability (CVE-2026-5523) Leads to Account Takeover
3 TTPs 1 CVEThe Divi Form Builder plugin for WordPress versions up to 5.1.8 is vulnerable to Missing Authorization, allowing authenticated attackers with subscriber-level access to change the email and password of any user, including administrators, by exploiting improper authorization checks in the update_user() and handle_register_submission() functions, enabling complete account takeover.
Critical RCE Vulnerability in Blocksy Companion Pro WordPress Plugin (CVE-2026-58480)
1 rule 3 TTPs 2 CVEs 1 IOCAn unauthenticated arbitrary file upload vulnerability (CVE-2026-58480) in Blocksy Companion Pro plugin for WordPress versions prior to 2.1.47 allows attackers to bypass extension validation via double-extension files, leading to remote code execution by forcing the web server to execute uploaded PHP files.
CVE-2026-5356: LatePoint WordPress Plugin Improper Input Validation Leading to Arbitrary Payments
2 TTPs 1 CVEAn improper input validation vulnerability (CVE-2026-5356) in the LatePoint - Calendar Booking Plugin for Appointments and Events for WordPress, versions up to and including 5.4.0, allows unauthenticated attackers to exploit its Stripe Connect payment processor by supplying a previously succeeded PaymentIntent ID, resulting in the processing of arbitrary payments.
CVE-2026-6230: Tainacan WordPress Plugin SQL Injection Vulnerability
1 rule 1 TTP 1 CVEAn unauthenticated attacker can exploit CVE-2026-6230, a time-based blind SQL Injection vulnerability in the Tainacan plugin for WordPress (versions up to and including 1.0.3) via the 'geoquery' parameter, to append arbitrary SQL queries and exfiltrate sensitive information from the database due to insufficient input validation.
CVE-2026-6854 - WordPress My Calendar Plugin Time-Based Blind SQL Injection
1 rule 2 TTPs 1 CVEA time-based blind SQL Injection vulnerability exists in the My Calendar - Accessible Event Manager plugin for WordPress, affecting all versions up to and including 3.7.8. This flaw, located in the 'mc_auth' parameter, stems from insufficient input sanitization and improper SQL query preparation, allowing unauthenticated attackers to inject additional SQL queries to extract sensitive information from the underlying database.
CVE-2026-6818: VikBooking WordPress Plugin Stored XSS Vulnerability
1 rule 5 TTPs 1 CVEA stored cross-site scripting vulnerability (CVE-2026-6818) exists in the VikBooking Hotel Booking Engine & PMS plugin for WordPress, affecting versions up to and including 1.8.8, caused by insufficient input sanitization of the 'special_requests' parameter, enabling unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses an affected page, potentially leading to unauthorized data access, session hijacking, or defacement.
CVE-2026-3688: WordPress WCFM Membership Plugin Insecure Direct Object Reference
2 TTPs 1 CVEAuthenticated attackers with vendor-level access can exploit an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-3688) in the WCFM Membership - WooCommerce Memberships for Multivendor Marketplace plugin for WordPress to change any user's role to 'wcfm_vendor' by manipulating membership plans, leading to unauthorized privilege escalation.
CVE-2026-14495: DoLogin Security Plugin Authentication Bypass via Insufficient Randomness
2 TTPs 1 CVEThe DoLogin Security plugin for WordPress, in all versions up to and including 4.3, is vulnerable to authentication bypass (CVE-2026-14495) due to insufficient randomness in magic-link token generation, allowing unauthenticated attackers to brute-force and reconstruct valid passwordless login tokens for any user, including administrators, and gain full control.
CVE-2026-14489: WHMCS Bridge Plugin Arbitrary File Upload Leads to RCE
3 TTPs 1 CVEAuthenticated attackers with Custom-level access or higher can exploit CVE-2026-14489, a missing file type validation vulnerability (CWE-434) in the `connect()` function of the WHMCS Bridge plugin for WordPress versions up to and including 6.9, to upload arbitrary files, potentially leading to remote code execution.
CVE-2026-12153 — WP Learn Manager Plugin Authorization Bypass
1 rule 2 TTPs 1 CVEThe WP Learn Manager plugin for WordPress, in versions up to and including 1.1.8, is vulnerable to an authorization bypass (CVE-2026-12153) allowing unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository, potentially leading to full site compromise.
CVE-2026-6101 — Arbitrary File Write in AMP for WP Plugin for WordPress
1 TTP 1 CVEAn arbitrary file write vulnerability (CVE-2026-6101) exists in the AMP for WP – Accelerated Mobile Pages plugin for WordPress, affecting versions up to and including 1.1.12. This flaw, caused by unsafe ZIP file extraction and inadequate cleanup, allows authenticated attackers with Author-level access and administrator-granted permissions to write arbitrary files to web-accessible server locations, potentially leading to remote code execution.
WordPress Bricks Builder Theme - Unauthenticated RCE (CVE-2024-25600)
1 rule 2 TTPs 1 CVE 4 IOCsAn unauthenticated Remote Code Execution (RCE) vulnerability (CVE-2024-25600) exists in the WordPress Bricks Builder Theme up to version 1.9.6, allowing attackers to exploit the 'render_element' endpoint by first extracting a nonce from the page source, then injecting PHP code to execute arbitrary operating system commands on the underlying web server, with a public exploit now available.
CVE-2026-14345: Unauthenticated Remote Code Execution in WPFunnels WordPress Plugin
2 TTPs 1 CVEAn unauthenticated remote code execution vulnerability (CVE-2026-14345) exists in the WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress, affecting versions up to and including 3.12.7, allowing attackers to inject malicious PHP code into a log file via the 'postData' parameter, which is then executed when an administrator views the log.
WordPress WPZOOM Portfolio Plugin XSS Vulnerability (CVE-2026-49069)
1 rule 2 TTPs 1 CVE 2 IOCsA critical reflected cross-site scripting (XSS) vulnerability, CVE-2026-49069, affects the WPZOOM Portfolio plugin (version 1.4.21 and earlier) for WordPress, enabling unauthenticated attackers to inject malicious JavaScript into web pages via the `wpzoom_load_more_items` AJAX action, leading to client-side script execution in victims' browsers.
WP AutoSuggest 0.24 SQL Injection Vulnerability (CVE-2018-25434)
2 rules 1 TTP 1 CVEWP AutoSuggest version 0.24 contains an SQL injection vulnerability that allows an unauthenticated attacker to execute arbitrary SQL queries by injecting malicious code through the wpas_keys parameter via GET requests to autosuggest.php, potentially extracting sensitive database information.
GEO my WP WordPress Plugin SQL Injection Vulnerability (CVE-2026-9757)
2 rules 1 TTP 1 CVEThe GEO my WP plugin for WordPress is vulnerable to SQL Injection (CVE-2026-9757) via the 'swlatlng' and 'nelatlng' parameters, allowing unauthenticated attackers to extract sensitive information from the database by injecting SQL queries into a BETWEEN clause.
CVE-2026-7465: Spectra Gutenberg Blocks WordPress Plugin Remote Code Execution
2 rules 1 TTP 1 CVEThe Spectra Gutenberg Blocks WordPress plugin is vulnerable to remote code execution, allowing authenticated attackers with Contributor access or higher to execute arbitrary code by crafting a malicious two-block payload within post content.
CVE-2026-7459: Simple History WordPress Plugin Account Takeover Vulnerability
2 rules 1 TTP 1 CVECVE-2026-7459 is an authenticated account takeover vulnerability in the Simple History WordPress plugin where a subscriber-level user can read password reset emails and escalate privileges to an administrator account.
WP Travel Pro Plugin Vulnerable to Arbitrary User Deletion (CVE-2026-4290)
2 rules 1 TTP 1 CVEThe WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the REST API endpoint, allowing unauthenticated attackers to delete arbitrary user accounts due to a flawed permission check and lack of role validation.
Media Library Assistant WordPress Plugin vulnerable to CSRF (CVE-2026-6075)
2 rules 1 TTP 1 CVEThe Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery (CVE-2026-6075) due to missing nonce verification, allowing unauthenticated attackers to trick an administrator into performing unauthorized bulk actions.
CVE-2025-11262: WordPress Link Whisper Free Plugin Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS), allowing unauthenticated attackers to inject arbitrary web scripts into pages, which execute when a user accesses the injected page, affecting versions up to and including 0.9.0.
CVE-2026-3655: WordPress OTP Login Plugin Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVEThe OTP Login With Phone Number, OTP Verification plugin for WordPress versions 1.8.50 through 1.8.60 is vulnerable to authentication bypass due to improper validation of the Firebase session, allowing unauthenticated attackers to authenticate as arbitrary users, including administrators, by supplying a victim's phone number.
WooCommerce Infinite Scroll Plugin Vulnerable to PHP Object Injection (CVE-2025-11993)
2 rules 1 TTP 1 CVEThe WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection (CVE-2025-11993) due to deserialization of untrusted data in the 'import_settings' function, potentially leading to arbitrary code execution if a suitable POP chain is present.
CVE-2026-8732 WP Maps Pro Plugin Privilege Escalation via Administrator Account Creation
2 rules 1 TTP 1 CVEThe WP Maps Pro plugin for WordPress is vulnerable to privilege escalation (CVE-2026-8732), allowing unauthenticated attackers to create administrator accounts and take over vulnerable sites.
CVE-2026-8809: Advanced Custom Fields: Extended WordPress Plugin Privilege Escalation
2 rules 1 TTP 1 CVEThe Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation (CVE-2026-8809), allowing an unauthenticated attacker to create an administrator-level user by bypassing validation in versions up to 0.9.2.5 if a specific form is exposed.
CVE-2026-8380: WordPress Frontend File Manager Arbitrary Post Deletion
2 rules 1 TTPCVE-2026-8380 is a critical authorization bypass vulnerability in the WordPress Frontend File Manager plugin <= 23.6 that allows authenticated low-privilege users, or unauthenticated users with guest uploads enabled, to permanently delete arbitrary WordPress posts, pages, attachments, and custom post types.
CVE-2026-6226 - Frontend Admin WordPress Plugin Unauthenticated Privilege Escalation
2 rules 1 TTP 1 CVEThe Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2, allowing attackers to create administrator accounts by injecting a custom form configuration with a spoofed role field.
CVE-2026-9227: GutenBee WordPress Plugin Arbitrary File Upload
2 rules 1 CVEThe GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level access to achieve remote code execution by uploading executable files with double extensions.
CVE-2026-7797: WordPress Simply Schedule Appointments Plugin Time-Based Blind SQL Injection
2 rules 1 TTP 1 CVEThe Appointment Booking Calendar WordPress plugin is vulnerable to time-based blind SQL Injection (CVE-2026-7797) via the 'append_where_sql' parameter, allowing unauthenticated attackers to extract sensitive information from the database by injecting SQL queries through the /appointments/bulk REST endpoint with a specific request format.
WordPress SlimStat Analytics Plugin Stored XSS Vulnerability (CVE-2026-7634)
2 rules 1 TTP 1 CVEThe SlimStat Analytics plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via the User-Agent header, allowing unauthenticated attackers to inject arbitrary web scripts if the 'show_complete_user_agent_tooltip' setting is enabled.
HT Contact Form WordPress Plugin Vulnerable to Stored XSS (CVE-2026-7052)
2 rules 1 TTP 1 CVEThe HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting (CVE-2026-7052) via the 'file_upload' parameter in versions up to 2.8.2, allowing unauthenticated attackers to inject arbitrary web scripts.
WP Contact Form 7 DB Handler Plugin CSRF leading to Arbitrary File Deletion (CVE-2026-6455)
2 rules 3 TTPs 1 CVEThe WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF), leading to arbitrary file deletion via SQL injection and PHP object injection due to missing nonce verification and unsafe deserialization, allowing attackers to delete arbitrary files on the server.
Crawlomatic Multipage Scraper Post Generator Plugin RCE (CVE-2026-9009)
2 rules 1 TTP 1 CVEThe Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to remote code execution (RCE) via the 'callback_raw' shortcode attribute, allowing authenticated attackers with author-level access or higher to execute arbitrary code on the server.
CVE-2026-8832 - WPCode WordPress Plugin Remote Code Execution Vulnerability
2 rules 1 TTP 1 CVEThe WPCode WordPress plugin before or equal to 2.3.5 is vulnerable to remote code execution due to missing capability restrictions on the 'wpcode' custom post type, allowing authenticated attackers with author-level access to execute arbitrary PHP code via XML-RPC.
HBook WordPress Plugin Stored XSS Vulnerability (CVE-2026-8143)
2 rules 1 TTP 1 CVEThe HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters (CVE-2026-8143) in versions up to 2.1.6, potentially leading to arbitrary script execution in the administrator's browser.
affiliate-toolkit WordPress Plugin RCE via BladeOne Template Injection (CVE-2026-6169)
2 rules 1 TTP 1 CVEThe affiliate-toolkit plugin for WordPress is vulnerable to remote code execution (CVE-2026-6169) due to the use of the BladeOne templating engine's runString() method, which allows authenticated attackers with Editor-level access or higher to execute arbitrary PHP code by injecting it into a plugin template.
LiteSpeed Cache Plugin Stored XSS Vulnerability (CVE-2026-3375)
1 rule 1 TTP 1 CVEThe LiteSpeed Cache plugin for WordPress is vulnerable to stored Cross-Site Scripting (XSS) via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints, affecting versions up to 7.7, allowing unauthenticated attackers to inject arbitrary JavaScript into CCSS/UCSS content by bypassing IP-based access controls.
CVE-2026-9200: WordPress Query Shortcode Plugin Vulnerable to Local File Inclusion
2 rules 2 TTPs 1 CVEThe Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion (CVE-2026-9200) in versions up to 0.2.1, allowing authenticated attackers with contributor-level access and above to include and execute arbitrary PHP files on the server, potentially leading to privilege escalation and code execution.
CVE-2026-8994 - WordPress Login with NEAR Plugin Authentication Bypass
2 rules 1 TTP 1 CVEThe Login with NEAR plugin for WordPress is vulnerable to authentication bypass due to the `ajaxLoginWithNear()` function issuing valid authentication cookies based on a substring check of the `account` POST parameter, allowing unauthenticated attackers to log in as existing users or create new accounts.
CVE-2026-8787: WordPress Firebase Support & Chat Management Plugin Privilege Escalation
2 rules 1 TTP 1 CVEThe Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation (CVE-2026-8787) where an authenticated attacker with Subscriber-level access can log in as any existing user, including an Administrator, by submitting that user's email address to the `acb_firebase_auth` AJAX action without proper ownership verification, leading to full account takeover.
CVE-2026-8760: WordPress Login with OTP Plugin Authentication Bypass
2 rules 1 TTP 2 CVEsThe Login with OTP plugin for WordPress is vulnerable to authentication bypass due to an incomplete fix for CVE-2024-11178, allowing unauthenticated attackers to brute-force OTP codes and gain administrative access.
WordPress Temporary Login Plugin Authentication Bypass Vulnerability
2 rules 1 TTPA public exploit is available for WordPress Temporary Login Plugin version 1.0.0, which demonstrates an authentication bypass vulnerability that can lead to account takeover, increasing the risk for unpatched systems.
WordPress Ultimate Form Builder Lite Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEWordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability (CVE-2018-25352) that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter, potentially leading to privilege escalation.
WordPress Contact Form Maker Plugin SQL Injection Vulnerability (CVE-2018-25347)
2 rules 1 TTP 1 CVEWordPress Contact Form Maker Plugin version 1.12.20 is vulnerable to SQL injection, enabling authenticated attackers to manipulate database queries via AJAX actions (FormMakerSQLMapping and generete_csv_fmc) by injecting malicious SQL code through the 'name' and 'search_labels' parameters, potentially extracting sensitive database information or escalating privileges.
WordPress Form Maker Plugin SQL Injection Vulnerability (CVE-2018-25346)
2 rules 1 TTP 1 CVEWordPress Form Maker Plugin version 1.12.24 and below is vulnerable to SQL injection, allowing authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv actions via crafted POST requests, potentially leading to data extraction, modification, or privilege escalation.
WooCommerce PayPal Payments Plugin Vulnerable to Order Manipulation and Information Disclosure (CVE-2026-9284)
2 rules 1 TTP 1 CVEThe WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on WC-AJAX endpoints, allowing attackers to manipulate order payment flows and exfiltrate sensitive order details (CVE-2026-9284).
CVE-2026-6898: Wishlist Member WordPress Plugin Vulnerability Leads to Site Takeover
2 rules 4 TTPs 1 CVEThe Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check (CVE-2026-6898), allowing authenticated attackers with subscriber-level access or higher to update the REST API Secret Key, create administrator accounts, and achieve complete site takeover.
CVE-2026-6897: Wishlist Member Plugin Vulnerability Leads to WordPress Site Takeover
2 rules 3 TTPs 1 CVECVE-2026-6897 is a critical vulnerability in the Wishlist Member plugin for WordPress, allowing authenticated attackers with subscriber-level access to modify plugin settings, including the REST API secret key, ultimately enabling them to create administrator accounts and take over the entire site.
WishList Member WordPress Plugin Missing Authorization Leads to Privilege Escalation (CVE-2026-6895)
2 rules 3 TTPs 1 CVEThe WishList Member plugin for WordPress is vulnerable to Missing Authorization, allowing attackers to obtain the REST API Secret Key and escalate privileges to administrator.
WishList Member Plugin Privilege Escalation via Missing Authorization (CVE-2026-6419)
2 rules 1 TTP 1 CVEThe WishList Member plugin for WordPress is vulnerable to privilege escalation (CVE-2026-6419) due to a missing capability and nonce check in the ajax_get_screen() function, allowing authenticated attackers with subscriber-level access to retrieve the plugin's REST API Secret Key and create administrator accounts, leading to complete site takeover.
CVE-2026-27384: W3 Total Cache Unauthenticated RCE via eval() Code Injection
2 rules 1 TTPA public exploit has been published for CVE-2026-27384, a critical unauthenticated remote code execution vulnerability in the W3 Total Cache WordPress plugin.
Royal Elementor Addons Vulnerability Allows Cross-Site Scripting
2 rules 1 TTPA remote, unauthenticated attacker can exploit a cross-site scripting (XSS) vulnerability in the Royal Elementor Addons plugin for WordPress.
CVE-2026-9011: Ditty WordPress Plugin Authorization Bypass Vulnerability
2 rules 1 TTP 1 CVEThe Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress versions up to 3.1.65 is vulnerable to an authorization bypass (CVE-2026-9011) that allows unauthenticated attackers to retrieve the full content of non-public Dittys by exploiting the ditty_init AJAX endpoint.
AudioIgniter WordPress Plugin Vulnerable to Insecure Direct Object Reference (CVE-2026-8679)
2 rules 1 TTPThe AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference (CVE-2026-8679) in versions up to 2.0.2, allowing unauthenticated attackers to view track metadata of any playlist, regardless of its status.
Easy Elements for Elementor Plugin Privilege Escalation (CVE-2026-9018)
2 rules 1 TTP 1 CVECVE-2026-9018 allows unauthenticated attackers to escalate privileges to administrator by exploiting a vulnerability in the Easy Elements for Elementor plugin, which lacks proper input validation during user registration.
CVE-2026-6960: BookingPress Pro Plugin Arbitrary File Upload Leading to Potential RCE
2 rules 3 TTPs 1 CVEThe BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in versions up to 5.6, allowing unauthenticated attackers to upload arbitrary files and potentially achieve remote code execution if a signature custom field is added to the booking form.
Divi Form Builder Unauthenticated Privilege Escalation via CVE-2026-5118
2 rules 1 TTP 2 IOCsCVE-2026-5118 is a critical vulnerability in the Divi Form Builder WordPress plugin (versions 5.1.2 and earlier) that allows unauthenticated attackers to create administrator accounts directly through the registration form, leading to full site takeover.
CVE-2026-6279 - Avada Builder Plugin Unauthenticated RCE via PHP Function Injection
2 rules 1 TTP 1 CVEThe Avada Builder (fusion-builder) plugin for WordPress is vulnerable to unauthenticated remote code execution (RCE) due to PHP function injection, allowing attackers to execute arbitrary code on affected sites.
CVE-2026-7613: Cost of Goods by PixelYourSite WordPress Plugin Stored XSS
2 rules 1 CVEThe Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an injected page.
AcyMailing WordPress Plugin Missing Authorization Vulnerability (CVE-2026-5200)
2 rules 2 TTPs 1 CVEThe AcyMailing plugin for WordPress is vulnerable to a missing authorization issue (CVE-2026-5200), allowing authenticated attackers with subscriber-level access to modify privileged AcyMailing configuration, export subscriber secret keys, and potentially achieve administrator account takeover if the administrator's email address is known.
Advanced Database Cleaner Premium WordPress Plugin Vulnerable to Local File Inclusion (CVE-2026-7522)
2 rules 2 TTPs 1 CVEThe Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion (LFI) in versions up to 4.1.0, allowing authenticated attackers with subscriber-level access to include and execute arbitrary PHP files on the server via the 'template' parameter, potentially leading to access control bypass, sensitive data access, or code execution.
CVE-2026-7637 - Boost Plugin for WordPress PHP Object Injection
2 rules 1 TTP 1 CVEThe Boost plugin for WordPress is vulnerable to PHP Object Injection (CVE-2026-7637) due to deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie, potentially leading to arbitrary code execution if a suitable property-oriented programming (POP) chain is present.
CVE-2026-9010 - WordPress Boost Plugin Time-Based SQL Injection
1 rule 1 TTP 1 CVEThe Boost plugin for WordPress is vulnerable to time-based SQL Injection (CVE-2026-9010) via the 'current_url' and 'user_name' parameters in versions up to 2.0.3, allowing unauthenticated attackers to extract sensitive information from the database due to insufficient input sanitization.
CVE-2026-7467: WordPress Read More & Accordion Plugin Privilege Escalation
2 rules 1 TTP 1 CVEThe Read More & Accordion plugin for WordPress is vulnerable to privilege escalation due to insufficient restrictions on database table writes and data validation during import, allowing authenticated attackers to create administrator accounts.
CVE-2026-6456 - WordPress Account Switcher Plugin Privilege Escalation
2 rules 1 TTP 1 CVEThe Account Switcher plugin for WordPress is vulnerable to privilege escalation (CVE-2026-6456) due to a loose comparison and lack of validation on the `rememberLogin` REST API endpoint, allowing authenticated attackers to gain administrator privileges.
Creative Mail WordPress Plugin Vulnerable to SQL Injection (CVE-2026-3985)
2 rules 1 TTP 1 CVEThe Creative Mail plugin for WordPress is vulnerable to SQL Injection due to insufficient escaping of the 'checkout_uuid' parameter and lack of sufficient preparation on the SQL query in the `has_checkout_consent()` method, allowing unauthenticated attackers to extract sensitive information from the database.
CVE-2026-7284 - Easy Elements for Elementor WordPress Plugin Privilege Escalation
2 rules 1 TTP 1 CVEThe Easy Elements for Elementor plugin for WordPress is vulnerable to privilege escalation (CVE-2026-7284) due to unrestricted user role assignment during registration, allowing unauthenticated attackers to gain administrator access.
ProSolution WP Client Plugin Arbitrary File Upload Vulnerability (CVE-2026-6555)
2 rules 1 TTP 1 CVEThe ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file upload (CVE-2026-6555) due to a validation mismatch, allowing unauthenticated attackers to upload malicious PHP files leading to remote code execution.
WordPress Kirki Plugin Arbitrary File Deletion (CVE-2026-8073)
2 rules 1 TTP 1 CVEThe Kirki plugin for WordPress is vulnerable to arbitrary file deletion via CVE-2026-8073 due to insufficient file path validation and a missing capability check in the 'downloadZIP' function, allowing unauthenticated attackers to delete files within the WordPress uploads directory.
Funnel Builder for WooCommerce Checkout Missing Authorization Vulnerability (CVE-2026-47100)
2 rules 1 CVEFunnel Builder for WooCommerce Checkout versions prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and inject malicious JavaScript, impacting checkout page visitors.
Contest Gallery WordPress Plugin SQL Injection Vulnerability (CVE-2026-8912)
2 rules 1 TTP 1 CVEThe Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to 28.1.6, allowing unauthenticated attackers to extract sensitive information from the database.
Piotnet Forms WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-4883)
2 rules 1 TTP 1 CVEThe Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function, allowing unauthenticated attackers to upload arbitrary files and potentially achieve remote code execution.
CVE-2026-4885: Piotnet Addons for Elementor Pro WordPress Plugin Arbitrary File Upload Vulnerability
2 rules 1 TTP 1 CVEThe Piotnet Addons for Elementor Pro plugin for WordPress, versions up to 7.1.70, is vulnerable to unauthenticated arbitrary file upload due to insufficient file type validation in the 'pafe_ajax_form_builder' function, potentially leading to remote code execution.
WordPress WP with Spritz Plugin 1.0 Remote File Inclusion
2 rules 1 TTP 1 CVEThe WordPress WP with Spritz plugin version 1.0 is vulnerable to remote file inclusion (RFI), allowing unauthenticated attackers to read arbitrary files by injecting file paths into the `url` parameter of the `wp.spritz.content.filter.php` endpoint, potentially exposing sensitive system configuration and credentials.
CVE-2018-25326: Google Drive for WordPress Path Traversal Vulnerability
2 rules 1 TTP 1 CVEGoogle Drive for WordPress 2.2 is vulnerable to path traversal (CVE-2018-25326), allowing unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter.
WooCommerce CSV Importer Path Traversal File Deletion (CVE-2018-25325)
2 rules 1 TTP 1 CVEWooCommerce CSV Importer 3.3.6 contains a path traversal vulnerability (CVE-2018-25325) that allows registered users to delete arbitrary files by submitting crafted filenames via the delete_export_file AJAX action.
CVE-2018-25335 - WordPress Peugeot Music Plugin Arbitrary File Upload Vulnerability
2 rules 1 TTP 1 CVEWordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability (CVE-2018-25335) that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint, leading to potential code execution.
CVE-2026-8719: Privilege Escalation Vulnerability in The AI Engine WordPress Plugin
2 rules 1 TTP 1 CVEThe AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin is vulnerable to privilege escalation (CVE-2026-8719) due to missing capability enforcement, allowing authenticated users (Subscriber+) to invoke admin-level MCP tools and gain administrator privileges.
WordPress Backup and Restore Plugin Arbitrary File Deletion (CVE-2021-47979)
2 rules 1 TTP 1 CVEWordPress Backup and Restore plugin 1.0.3 contains an arbitrary file deletion vulnerability (CVE-2021-47979) allowing authenticated attackers to delete files by manipulating parameters in AJAX requests to admin-ajax.php.
WordPress Anti-Malware Security and Bruteforce Firewall Directory Traversal Vulnerability
2 rules 1 TTP 1 CVEWordPress Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability (CVE-2021-47977) that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter in requests to admin-ajax.php.
WP Learn Manager Stored XSS Vulnerability (CVE-2021-47975)
1 rule 1 TTP 1 CVEWP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability (CVE-2021-47975) that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter via a POST request to the jslm_fieldordering page, resulting in arbitrary JavaScript execution when administrators view the field ordering interface.
Supsystic Digital Publications Path Traversal and Stored XSS Vulnerability (CVE-2020-37245)
2 rules 1 TTP 1 CVESupsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field, allowing attackers to access sensitive files, and a stored XSS vulnerability due to improper input sanitization, leading to arbitrary script execution in the context of affected users (CVE-2020-37245).
CVE-2020-37244: Supsystic Membership 1.4.7 Unauthenticated SQL Injection Vulnerability
2 rules 1 TTP 1 CVESupsystic Membership version 1.4.7 is vulnerable to SQL injection (CVE-2020-37244), allowing unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters, potentially extracting sensitive database information.
Supsystic Pricing Table Plugin <= 1.8.7 SQL Injection Vulnerability (CVE-2020-37243)
2 rules 1 TTP 1 CVESupsystic Pricing Table plugin version 1.8.7 contains an SQL injection vulnerability via the 'sidx' GET parameter, enabling unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl action, as well as stored XSS vulnerabilities.
Supsystic Ultimate Maps SQL Injection Vulnerability (CVE-2020-37242)
1 rule 1 TTP 1 CVESupsystic Ultimate Maps 1.1.12 is vulnerable to SQL injection via the 'sidx' GET parameter, allowing unauthenticated attackers to execute arbitrary SQL queries and extract sensitive database information.
HS Brand Logo Slider 2.1 Unrestricted File Upload Vulnerability (CVE-2020-37227)
2 rules 1 TTP 1 CVEHS Brand Logo Slider version 2.1 contains an unrestricted file upload vulnerability (CVE-2020-37227) allowing authenticated users to bypass client-side validation and upload arbitrary files, leading to remote code execution by intercepting upload requests and renaming files to executable extensions.
CVE-2021-47959: WPGraphQL Plugin Denial of Service via Batched Queries
2 rules 1 TTP 1 CVEThe WordPress Plugin WPGraphQL version 1.3.5 is vulnerable to a denial-of-service attack where unauthenticated attackers can exhaust server resources by sending batched GraphQL queries with duplicated fields, potentially causing server out-of-memory conditions and MySQL connection errors.
CVE-2021-47965: WordPress WP Super Edit Plugin Unrestricted File Upload
2 rules 2 TTPs 1 CVEWordPress WP Super Edit plugin version 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component, allowing unauthenticated attackers to upload arbitrary files leading to remote code execution and complete system compromise.
CVE-2026-6403: Quick Playground Plugin for WordPress Path Traversal Vulnerability
2 rules 1 TTP 1 CVEThe Quick Playground plugin for WordPress, versions up to 1.3.3, is vulnerable to a path traversal vulnerability (CVE-2026-6403) in the qckply_zip_theme() function, allowing unauthenticated attackers to create ZIP archives containing arbitrary server files, including wp-config.
CVE-2026-6228 - WordPress Frontend Admin Plugin Privilege Escalation
2 rules 1 TTP 1 CVEThe Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation (CVE-2026-6228) in versions up to and including 3.28.36, allowing unauthenticated attackers to gain administrator privileges.
WordPress Form Notify Plugin Authentication Bypass Vulnerability (CVE-2026-5229)
2 rules 1 TTP 1 CVEThe Form Notify plugin for WordPress is vulnerable to CVE-2026-5229, an authentication bypass, due to trusting user-controlled cookie data after a LINE OAuth login, allowing unauthenticated attackers to gain administrative access.
CVE-2026-4094: FOX – Currency Switcher Professional for WooCommerce Plugin Vulnerability
2 rules 1 TTP 1 CVEThe FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss (CVE-2026-4094) due to a missing capability check, allowing authenticated attackers with Contributor-level access or higher to delete the multi-currency configuration.
CVE-2026-4031 - Database Backup for WordPress Plugin Authorization Bypass
2 rules 1 TTP 1 CVECVE-2026-4031 is an authorization bypass vulnerability in the Database Backup for WordPress plugin (<= 2.5.2) that allows unauthenticated attackers to intercept database backup files by manipulating the backup directory via the wp_db_temp_dir parameter, leading to sensitive information exposure.
Database Backup for WordPress Plugin Arbitrary File Read and Deletion Vulnerability (CVE-2026-4030)
2 rules 1 CVEThe Database Backup for WordPress plugin before 2.5.3 is vulnerable to unauthenticated arbitrary file read and deletion due to improper authorization checks and user-controlled backup directories, leading to sensitive information exposure and potential site takeover on WordPress Multisite environments.
CVE-2026-4029: Database Backup for WordPress Plugin Unauthorized Database Export
2 rules 1 TTP 1 CVEThe Database Backup for WordPress plugin up to version 2.5.2 is vulnerable to unauthorized database export due to improper authorization enforcement, allowing unauthenticated attackers to export database tables in WordPress Multisite environments.
InfusedWoo Pro WordPress Plugin Arbitrary File Read Vulnerability (CVE-2026-6514)
2 rules 1 TTP 1 CVEThe InfusedWoo Pro plugin for WordPress is vulnerable to arbitrary file read in versions up to 5.1.2, allowing unauthenticated attackers to make web requests to arbitrary locations, potentially querying and modifying information from internal services.
InfusedWoo Pro Plugin for WordPress Authorization Bypass (CVE-2026-6512)
2 rules 1 TTP 1 CVEThe InfusedWoo Pro plugin for WordPress is vulnerable to an authorization bypass (CVE-2026-6512) in versions up to 5.1.2, allowing unauthenticated attackers to delete posts, pages, products, orders, comments, and change post statuses.
CVE-2026-6506: InfusedWoo Pro WordPress Plugin Privilege Escalation
2 rules 1 TTP 1 CVEThe InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in versions up to 5.1.2 due to missing authorization checks in the infusedwoo_gdpr_upddata() function, allowing authenticated attackers to grant themselves administrator privileges.
Fluent Forms WordPress Plugin IDOR Vulnerability (CVE-2026-5395)
2 rules 2 TTPs 1 CVEThe Fluent Forms WordPress plugin through 6.2.0 is vulnerable to Insecure Direct Object Reference (IDOR), allowing authenticated users with manager-level access or higher to bypass form-level access controls, export arbitrary database tables, and enumerate table names via error messages, as tracked by CVE-2026-5395.
CVE-2026-3892 - WordPress Motors Plugin Arbitrary File Deletion
1 rule 1 TTP 1 CVEThe Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in versions up to 1.4.107 due to insufficient file path validation in the become-dealer logo upload flow, allowing authenticated attackers with subscriber level access and above to delete arbitrary files on the server.
ManageWP Worker Plugin Vulnerable to Stored XSS via HTTP Header
2 rules 1 TTP 1 CVEThe ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'MWP-Key-Name' HTTP request header, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator visits the plugin's connection management page with debug parameters; this affects all versions up to and including 4.9.31.
CVE-2026-6510: InfusedWoo Pro WordPress Plugin Privilege Escalation
1 rule 1 TTP 1 CVEThe InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler, allowing unauthenticated attackers to create malicious automation recipes for auto-login actions.
Fluent Forms Plugin Authorization Bypass via User-Controlled Key (CVE-2026-5396)
2 rules 2 TTPs 1 CVEThe Fluent Forms plugin for WordPress is vulnerable to authorization bypass via a user-controlled key (CVE-2026-5396), allowing authenticated attackers with restricted access to specific forms to manipulate submissions of unauthorized forms by spoofing the 'form_id' parameter.
Burst Statistics WordPress Plugin Authentication Bypass (CVE-2026-8181)
1 rule 1 TTP 1 CVEThe Burst Statistics plugin for WordPress is vulnerable to authentication bypass, allowing unauthenticated attackers with knowledge of an administrator username to impersonate that administrator by supplying a random Basic Authentication password, leading to privilege escalation.
CVE-2026-6177 - Custom Twitter Feeds WordPress Plugin Stored XSS
2 rules 1 TTP 1 CVEThe Custom Twitter Feeds plugin for WordPress is vulnerable to stored cross-site scripting (XSS) in versions up to and including 2.5.4 due to insufficient output escaping, allowing unauthenticated attackers to inject arbitrary web scripts.
RTMKit Addons for Elementor WordPress Plugin LFI Vulnerability (CVE-2026-3425)
1 rule 2 TTPs 1 CVEThe RTMKit Addons for Elementor plugin for WordPress is vulnerable to local file inclusion (LFI) via the 'path' parameter in the 'get_content' AJAX action, allowing authenticated attackers with Author-level access or higher to include and execute arbitrary PHP files, leading to potential code execution.
CVE-2026-4798 - Avada Builder Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEThe Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection (CVE-2026-4798) via the ‘product_order’ parameter in versions up to 3.15.1, potentially allowing unauthenticated attackers to extract sensitive database information if WooCommerce was previously used and deactivated.
JoomSport WordPress Plugin Vulnerable to Time-Based Blind SQL Injection (CVE-2026-6929)
2 rules 1 TTP 1 CVEThe JoomSport plugin for WordPress is vulnerable to time-based blind SQL Injection (CVE-2026-6929) via the 'sortf' parameter in versions up to 5.7.7, allowing unauthenticated attackers to extract sensitive information from the database.
coreActivity: Activity Logging for WordPress Plugin Vulnerable to PHP Object Injection (CVE-2026-7635)
2 rules 1 TTP 1 CVEThe coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection (CVE-2026-7635), allowing unauthenticated attackers to inject a crafted PHP serialized payload via the User-Agent header, leading to a persistent Denial of Service condition.
CVE-2026-5371: MonsterInsights WordPress Plugin Unauthorized Access Vulnerability
2 rules 2 TTPs 1 CVEThe MonsterInsights WordPress plugin through 10.1.2 is vulnerable to unauthorized access and data modification, allowing authenticated attackers with subscriber-level access to retrieve Google OAuth tokens and reset Google Ads integration due to missing capability checks on `get_ads_access_token()` and `reset_experience()` functions.
WordPress Court Reservation Plugin SQL Injection Vulnerability (CVE-2026-1250)
2 rules 1 TTP 1 CVEThe Court Reservation – Manage Your Court Bookings Online plugin for WordPress versions 1.10.11 and earlier are vulnerable to SQL injection via the 'id' parameter, enabling unauthenticated attackers to extract sensitive database information.
CVE-2026-6690: LifePress WordPress Plugin Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe LifePress plugin for WordPress is vulnerable to stored cross-site scripting (XSS) due to insufficient input sanitization and output escaping within the `lp_update_mds` AJAX action, allowing unauthenticated attackers to inject arbitrary web scripts via the 'n' parameter that execute when a user accesses the injected page; this affects versions up to and including 2.2.2.
AIWU WordPress Plugin Vulnerable to SQL Injection (CVE-2026-2993)
2 rules 1 TTP 1 CVEThe AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection (CVE-2026-2993) in versions up to 1.4.17, allowing unauthenticated attackers to extract sensitive information from the database.
CVE-2021-47941: WordPress Survey & Poll Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEWordPress Plugin Survey & Poll version 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter, potentially leading to sensitive data extraction.
CVE-2021-47940: WordPress Download From Files Plugin Arbitrary File Upload
1 rule 1 TTP 1 CVEWordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability (CVE-2021-47940) that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action.
CVE-2021-47933 - WordPress MStore API Arbitrary File Upload
2 rules 1 TTP 1 CVEWordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability, allowing unauthenticated attackers to upload malicious files via POST requests to the REST API, leading to remote code execution.
CVE-2021-47932: WordPress TheCartPress Unauthenticated Privilege Escalation
2 rules 1 TTP 1 CVEWordPress TheCartPress version 1.5.3.6 contains an unauthenticated privilege escalation vulnerability, CVE-2021-47932, allowing attackers to create administrator accounts via crafted POST requests to the AJAX handler.
WordPress Auto Affiliate Links Plugin Stored XSS Vulnerability (CVE-2026-7330)
2 rules 1 TTP 1 CVEThe Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to 6.8.8 due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into the admin statistics page.
WordPress User Frontend Plugin Deserialization Vulnerability (CVE-2026-5127)
2 rules 1 TTP 1 CVEThe User Frontend WordPress plugin is vulnerable to authenticated deserialization, allowing subscriber-level attackers to inject PHP objects for potential arbitrary code execution.
WordPress Slider Revolution Plugin Arbitrary File Upload Vulnerability
2 rules 1 TTP 1 CVEThe Slider Revolution plugin for WordPress is vulnerable to arbitrary file upload due to insufficient file type validation, allowing authenticated attackers with subscriber-level access or higher to upload executable files, potentially leading to remote code execution.
BetterDocs Pro Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEThe BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions, allowing unauthenticated attackers to extract sensitive information from the database.
Gravity Bookings Premium Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEThe Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in versions up to 2.5.9, allowing unauthenticated attackers to extract sensitive information from the database.
LatePoint WordPress Plugin Vulnerable to Stored XSS (CVE-2026-7448)
2 rules 1 TTP 1 CVEThe LatePoint WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the 'first_name' parameter, affecting versions up to 5.5.0, allowing unauthenticated attackers to inject malicious scripts.
WeePie Cookie Allow Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEThe WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in versions up to 3.4.11, allowing unauthenticated attackers to extract sensitive information from the database.
WordPress Backup Migration Plugin Unauthenticated Database Backup Download
2 rules 1 TTP 1 CVEWordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability allowing unauthenticated attackers to download complete database backups by accessing predictable file paths.
Forminator Forms Plugin Path Traversal Vulnerability
2 rules 1 TTP 1 CVEThe Forminator Forms WordPress plugin is vulnerable to an unauthenticated path traversal that allows reading arbitrary files on the server when specific features are enabled.
AWP Classifieds WordPress Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEThe AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.5, potentially allowing unauthenticated attackers to extract sensitive information from the database.
WordPress Mentoring Plugin Privilege Escalation Vulnerability
2 rules 1 TTP 1 CVEThe Mentoring plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated attackers to register with administrator-level user accounts due to improper role restriction in the mentoring_process_registration() function.
Contact Form 7 WordPress Plugin Uncontrolled Resource Consumption Vulnerability
2 rules 1 TTP 1 CVEThe Contact Form 7 WordPress plugin through version 2.6.7 is vulnerable to uncontrolled resource consumption, allowing unauthenticated attackers to exhaust server memory and crash the PHP process by supplying an arbitrarily large integer value to the REST API endpoint, leading to unbounded loop execution.
WordPress Easy PayPal Events & Tickets Plugin Information Disclosure Vulnerability
2 rules 1 TTP 1 CVEAn information disclosure vulnerability in the Easy PayPal Events & Tickets WordPress plugin (versions 1.3 and earlier) allows unauthenticated attackers to enumerate and retrieve all customer order records via the scan_qr.php endpoint.
WordPress Easy PayPal Events & Tickets Plugin Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVE 1 IOCAn unauthenticated remote attacker can exploit a hardcoded authentication bypass vulnerability in the Easy PayPal Events & Tickets plugin for WordPress (versions 1.3 and earlier) by providing 'test' as the hash parameter, allowing retrieval of sensitive order details.
NEX-Forms WordPress Plugin Vulnerable to Stored Cross-Site Scripting (CVE-2026-5063)
2 rules 1 TTP 1 CVEThe NEX-Forms WordPress plugin is vulnerable to stored XSS via POST parameter key names, allowing unauthenticated attackers to inject arbitrary web scripts.
WordPress WCFM Plugin Vulnerable to IDOR Leading to Account Deletion
2 rules 1 TTP 1 CVEThe WCFM plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) that allows authenticated attackers with Vendor-level access or higher to delete arbitrary users, including administrators.
Salon Booking System WordPress Plugin Arbitrary File Read Vulnerability
2 rules 1 TTP 1 CVEThe Salon Booking System WordPress plugin is vulnerable to arbitrary file read, allowing unauthenticated attackers to exfiltrate local files by manipulating file-field values in booking confirmation emails.
Paid Memberships Pro Plugin Vulnerability Allows Unauthorized Stripe Webhook Modification
2 rules 3 TTPs 1 CVEThe Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification of Stripe webhook configurations due to missing capability checks, allowing authenticated attackers with Subscriber-level access to disrupt payment processing.
Geo Mashup WordPress Plugin Vulnerable to Time-Based SQL Injection (CVE-2026-4062)
2 rules 1 TTP 1 CVEThe Geo Mashup WordPress plugin is vulnerable to Time-Based SQL Injection due to insufficient input sanitization, allowing unauthenticated attackers to extract sensitive database information.
Geo Mashup WordPress Plugin Vulnerable to Time-Based SQL Injection (CVE-2026-4061)
2 rules 1 TTP 1 CVEA time-based SQL injection vulnerability (CVE-2026-4061) exists in the Geo Mashup WordPress plugin (<= 1.13.18) due to insufficient sanitization of the 'map_post_type' parameter, enabling unauthenticated attackers to extract sensitive information via time-based blind SQL injection if the Geo Search feature is enabled.
WordPress Widget Options Plugin Remote Code Execution Vulnerability (CVE-2026-2052)
2 rules 1 TTP 1 CVEThe Widget Options plugin for WordPress is vulnerable to Remote Code Execution (CVE-2026-2052) due to insufficient input sanitization in the Display Logic feature, allowing authenticated attackers with Contributor-level access and above to execute arbitrary code on the server.
PixelYourSite Pro WordPress Plugin SSRF Vulnerability (CVE-2026-7049)
2 rules 1 TTP 1 CVEThe PixelYourSite Pro WordPress plugin is vulnerable to server-side request forgery (SSRF), allowing unauthenticated attackers to make arbitrary web requests from the server, potentially querying or modifying internal services.
Gravity Forms Plugin Stored XSS Vulnerability (CVE-2026-5113)
2 rules 2 TTPs 1 CVEThe Gravity Forms plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via Consent field hidden inputs, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the entries list page.
WP Mail Gateway Plugin Vulnerability Leads to Privilege Escalation
2 rules 1 TTP 1 CVEThe WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check, allowing authenticated attackers to modify SMTP settings and escalate privileges.
WordPress User Verification Plugin Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVEThe User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in versions up to 2.0.46 due to a loose PHP comparison, allowing unauthenticated attackers to log in as any verified user by submitting a 'true' OTP value.
WordPress Import and Export Users Plugin Privilege Escalation Vulnerability
2 rules 1 TTP 1 CVEA privilege escalation vulnerability exists in the Import and export users and customers plugin for WordPress (versions <= 2.0.8) due to an incomplete blocklist allowing authenticated users to gain administrator privileges on subsites within a Multisite network.
WordPress User Registration Advanced Fields Plugin Arbitrary File Upload Vulnerability
2 rules 1 TTP 1 CVEThe User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation, allowing unauthenticated attackers to upload arbitrary files leading to potential remote code execution.
WP Editor Plugin CSRF Vulnerability
2 rules 1 TTP 1 CVEThe WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to 1.2.9.2, allowing unauthenticated attackers to overwrite arbitrary plugin and theme PHP files with malicious code by tricking a site administrator into clicking a link.
WordPress Temporary Login Plugin Authentication Bypass (CVE-2026-7567)
2 rules 1 TTP 1 CVEThe Temporary Login plugin for WordPress versions up to 1.0.0 is vulnerable to authentication bypass due to improper input validation, allowing unauthenticated attackers to log in as arbitrary temporary users by sending a specially crafted GET request.
BuddyPress Xprofile Custom Fields Type 2.6.3 Remote Code Execution via Arbitrary File Deletion
2 rules 1 TTP 1 CVECVE-2018-25308 is a remote code execution vulnerability in BuddyPress Xprofile Custom Fields Type 2.6.3 that allows authenticated users to delete arbitrary files on the server by manipulating POST parameters.
WordPress Create DB Tables Plugin Authorization Bypass Vulnerability (CVE-2026-4119)
2 rules 3 TTPs 1 CVEThe Create DB Tables plugin for WordPress versions 1.2.1 and earlier is vulnerable to an authorization bypass, allowing authenticated users to create and delete database tables without proper checks, potentially leading to complete site destruction.
WordPress HTTP Headers Plugin Remote Code Execution via File Path Manipulation (CVE-2026-4132)
2 rules 1 TTP 1 CVEThe HTTP Headers WordPress plugin is vulnerable to remote code execution (RCE) due to insufficient validation of the htpasswd file path and lack of sanitization of the username, allowing authenticated administrators to write arbitrary code to the server.
MetaSlider Responsive Slider Plugin Deserialization Vulnerability (CVE-2026-39467)
2 rules 1 TTP 1 CVEA deserialization of untrusted data vulnerability in the MetaSlider Responsive Slider plugin for WordPress (versions up to 3.106.0) allows for unauthenticated object injection, potentially leading to remote code execution.
Everest Forms Plugin Arbitrary File Read and Deletion Vulnerability
2 rules 3 TTPs 1 CVEThe Everest Forms plugin for WordPress is vulnerable to arbitrary file read and deletion, allowing unauthenticated attackers to access sensitive data or cause denial of service by manipulating the 'old_files' parameter in versions up to 3.4.4.
WP Customer Area Plugin Arbitrary File Read and Deletion Vulnerability
2 rules 1 TTP 1 CVEThe WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation, allowing authenticated attackers to read sensitive files or delete critical files leading to potential remote code execution.
Unlimited Elements for Elementor WordPress Plugin Arbitrary File Read (CVE-2026-4659)
2 rules 1 TTP 1 CVEThe Unlimited Elements for Elementor plugin for WordPress is vulnerable to arbitrary file read due to insufficient path traversal sanitization, allowing authenticated attackers to read sensitive files from the WordPress host.
Plisio Accept Cryptocurrencies Plugin Missing Authorization Vulnerability (CVE-2026-6372)
2 rules 1 TTP 1 CVE 1 IOCA missing authorization vulnerability in the Plisio Accept Cryptocurrencies with Plisio WordPress plugin (versions up to 2.0.5) allows attackers to bypass payment verification due to incorrectly configured access control security levels.
AcyMailing Plugin Privilege Escalation Vulnerability (CVE-2026-3614)
2 rules 1 TTP 1 CVEThe AcyMailing plugin for WordPress is vulnerable to privilege escalation (CVE-2026-3614), allowing authenticated attackers with subscriber-level access to gain administrative privileges.
Riaxe Product Customizer WordPress Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEThe Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter within 'product_data' of the `/wp-json/InkXEProductDesignerLite/add-item-to-cart` REST API endpoint, allowing unauthenticated attackers to extract sensitive information from the database.
Riaxe Product Customizer WordPress Plugin Privilege Escalation Vulnerability (CVE-2026-3596)
2 rules 2 TTPs 1 CVEThe Riaxe Product Customizer plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated attackers to update arbitrary WordPress options via a publicly accessible AJAX endpoint and escalate privileges to administrator.
WC Lovers WCFM Marketplace SQL Injection Vulnerability (CVE-2025-63029)
2 rules 1 TTP 1 CVE 1 IOCAn SQL Injection vulnerability, identified as CVE-2025-63029, exists in the WC Lovers WCFM Marketplace WordPress plugin up to version 3.7.1, potentially allowing attackers to execute arbitrary SQL queries.
Smart Post Show WordPress Plugin PHP Object Injection Vulnerability
2 rules 1 TTP 1 CVEThe Smart Post Show WordPress plugin versions 3.0.12 and earlier are vulnerable to PHP Object Injection via deserialization of untrusted input in the import_shortcodes() function, potentially leading to remote code execution if a suitable POP chain is present.
LearnPress WordPress Plugin Unauthorized Data Deletion Vulnerability (CVE-2026-4365)
2 rules 1 TTP 1 CVEThe LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function, allowing unauthenticated attackers to delete quiz answer options.
Case Theme User WordPress Plugin Local File Inclusion Vulnerability (CVE-2025-5804)
2 rules 1 TTP 1 CVECVE-2025-5804 is a PHP Local File Inclusion vulnerability in the Case Theme User WordPress plugin before version 1.0.4 due to improper filename control in include/require statements, potentially allowing attackers to execute arbitrary code by including malicious local files.
CactusThemes VideoPro Theme Local File Inclusion Vulnerability (CVE-2025-58913)
2 rules 1 TTP 1 CVECVE-2025-58913 is a PHP Local File Inclusion vulnerability in the CactusThemes VideoPro WordPress theme, affecting versions from n/a through 2.3.8.1 due to improper control of the filename for include/require statements, potentially allowing unauthorized file access.
wpForo Forum Plugin Arbitrary File Deletion Vulnerability (CVE-2026-5809)
2 rules 1 TTP 1 CVEThe wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion due to a logic flaw that allows authenticated users to delete arbitrary files writable by the PHP process by manipulating post metadata.
BuddyPress Groupblog Plugin Privilege Escalation Vulnerability (CVE-2026-5144)
2 rules 1 TTP 1 CVEThe BuddyPress Groupblog plugin for WordPress is vulnerable to privilege escalation (CVE-2026-5144), allowing a low-privileged user to gain administrator access on a WordPress Multisite network by manipulating group blog settings.
Zootemplate Cerato Theme Reflected XSS Vulnerability (CVE-2025-58920)
2 rules 1 TTP 1 CVE 1 IOCA reflected cross-site scripting (XSS) vulnerability exists in the Zootemplate Cerato WordPress theme (versions n/a through 2.2.18) due to improper neutralization of user-supplied input, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.
Gravity SMTP Plugin Missing Authorization Vulnerability (CVE-2026-4162)
2 rules 1 TTP 1 CVEThe Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization, allowing authenticated attackers with subscriber-level access or higher to uninstall/deactivate the plugin and delete plugin options, and is also exploitable via Cross-Site Request Forgery.
Perfmatters WordPress Plugin Arbitrary File Overwrite Vulnerability (CVE-2026-4351)
2 rules 2 TTPs 1 CVEThe Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal, allowing authenticated attackers with subscriber-level access to overwrite arbitrary files on the server with a fixed PHP docblock content, potentially causing denial of service.
Smart Slider 3 Pro Compromised Update Leads to Remote Code Execution
3 rules 9 TTPs 1 CVESmart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system allowing unauthenticated remote code execution and system takeover.
WordPress adivaha Travel Plugin SQL Injection Vulnerability (CVE-2023-54359)
2 rules 1 TTP 1 CVEThe WordPress adivaha Travel Plugin version 2.3 is vulnerable to time-based blind SQL injection via the 'pid' GET parameter, allowing unauthenticated attackers to inject SQL code through the /mobile-app/v3/ endpoint for potential data extraction or denial of service.
WooCommerce Ajax Product Filter Plugin Vulnerable to SQL Injection (CVE-2026-3396)
2 rules 1 TTP 1 CVEThe WCAPF - WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection (CVE-2026-3396) due to insufficient escaping and SQL query preparation, allowing unauthenticated attackers to extract sensitive information from the database in versions up to 4.2.3.
WordPress Plugin Vulnerability: Arbitrary File Upload in Gerador de Certificados – DevApps
2 rules 2 TTPs 1 CVEThe Gerador de Certificados – DevApps WordPress plugin is vulnerable to arbitrary file uploads due to missing file type validation, potentially leading to remote code execution.
Product Feed PRO for WooCommerce Plugin CSRF Vulnerability (CVE-2026-3499)
3 rules 1 TTP 1 CVEThe Product Feed PRO for WooCommerce WordPress plugin (versions 13.4.6-13.5.2.1) is vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing unauthenticated attackers to perform administrative actions by tricking an administrator into clicking a malicious link.
Everest Forms WordPress Plugin PHP Object Injection Vulnerability
2 rules 2 TTPs 1 CVEThe Everest Forms plugin for WordPress is vulnerable to PHP Object Injection (CVE-2026-3296) in versions up to 3.4.3, allowing unauthenticated attackers to execute arbitrary code by injecting serialized PHP objects via form fields.
CSRF Vulnerability in WordPress Under Construction Plugin (CVE-2026-34896)
2 rules 2 TTPs 1 CVEA cross-site request forgery (CSRF) vulnerability exists in the Analytify Under Construction, Coming Soon & Maintenance Mode WordPress plugin (versions n/a through 2.1.1), potentially allowing attackers to execute unauthorized actions on behalf of legitimate users.
Amelia WordPress Plugin IDOR Vulnerability CVE-2026-5465
2 rules 1 TTP 1 CVEThe Amelia WordPress plugin is vulnerable to an insecure direct object reference, allowing authenticated attackers with Provider-level access or higher to escalate privileges and gain persistence by taking over any WordPress account, including Administrator by manipulating the `externalId` field.
Ninja Forms File Upload Plugin Vulnerability Leads to RCE
2 rules 2 TTPs 1 CVEThe Ninja Forms File Uploads plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads due to missing file type validation, potentially leading to remote code execution.
Media Library Assistant WordPress Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEThe Media Library Assistant WordPress plugin through version 3.34 is vulnerable to SQL injection, allowing attackers to manipulate database queries.
WordPress Widgets for Social Photo Feed Plugin Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'feed_data' parameter, allowing unauthenticated attackers to inject arbitrary web scripts in pages that will execute when a user accesses the injected page.
ProfilePress WordPress Plugin Membership Payment Bypass Vulnerability
2 rules 1 TTP 1 CVEThe ProfilePress WordPress plugin before 4.16.12 is vulnerable to an unauthorized membership payment bypass, allowing authenticated attackers to obtain paid memberships without payment by manipulating subscription IDs during checkout.
Perfmatters WordPress Plugin Arbitrary File Deletion Vulnerability (CVE-2026-4350)
2 rules 1 TTP 1 CVEThe Perfmatters plugin for WordPress versions up to 2.5.9.1 is vulnerable to arbitrary file deletion via path traversal, allowing authenticated attackers with minimal privileges to delete sensitive files.
WordPress Webmention Plugin SSRF Vulnerability (CVE-2026-0686)
2 rules 1 TTP 1 CVEThe Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to 5.6.2, allowing unauthenticated attackers to make arbitrary web requests and potentially query or modify internal services.
MW WP Form WordPress Plugin Arbitrary File Move Vulnerability (CVE-2026-4347)
2 rules 2 TTPs 1 CVEThe MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation, allowing unauthenticated attackers to move arbitrary files on the server, potentially leading to remote code execution.
Query Monitor WordPress Plugin Vulnerable to Reflected XSS (CVE-2026-4267)
2 rules 1 TTP 1 CVEThe Query Monitor WordPress plugin is vulnerable to reflected cross-site scripting (XSS) due to insufficient input sanitization and output escaping of the '$_SERVER['REQUEST_URI']' parameter, allowing unauthenticated attackers to inject arbitrary web scripts.
Contact Form by Supsystic WordPress Plugin SSTI Vulnerability (CVE-2026-4257)
2 rules 1 TTP 1 CVEThe Contact Form by Supsystic WordPress plugin is vulnerable to Server-Side Template Injection (SSTI) via the `cfsPreFill` parameter, leading to unauthenticated Remote Code Execution (RCE).
Oxygen Theme WordPress Plugin Vulnerable to Server-Side Request Forgery (CVE-2025-12886)
2 rules 1 TTPThe Oxygen Theme for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to 6.0.8, allowing unauthenticated attackers to make arbitrary web requests via the laborator_calc_route AJAX action.
Fluent Booking WordPress Plugin Stored XSS Vulnerability
2 rules 1 TTPThe Fluent Booking plugin for WordPress is vulnerable to stored cross-site scripting (XSS) allowing unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page, affecting versions up to and including 2.0.01.
Blackhole for Bad Bots WordPress Plugin Stored XSS Vulnerability
2 rules 1 TTPThe Blackhole for Bad Bots WordPress plugin through version 3.8 is vulnerable to stored cross-site scripting (XSS) via the User-Agent HTTP header, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the plugin's admin page.
Masteriyo LMS WordPress Plugin Privilege Escalation Vulnerability
2 rules 1 TTPThe Masteriyo LMS plugin for WordPress is vulnerable to privilege escalation, allowing authenticated users with student-level access or higher to gain administrator privileges by manipulating the 'InstructorsController::prepare_object_for_database' function.
WP Job Portal Plugin Arbitrary File Deletion Vulnerability (CVE-2026-4758)
2 rules 3 TTPsThe WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with subscriber-level access or higher to delete arbitrary files, potentially leading to remote code execution.
WP Job Portal Plugin SQL Injection Vulnerability
2 rules 1 TTPThe WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter, allowing unauthenticated attackers to extract sensitive database information in versions up to 2.4.8.
ReviewX WordPress Plugin Arbitrary Method Call Vulnerability
2 rules 1 TTPThe ReviewX WordPress plugin is vulnerable to arbitrary method calls, allowing unauthenticated attackers to potentially achieve remote code execution.
Contest Gallery WordPress Plugin Authentication Bypass Vulnerability (CVE-2026-4021)
2 rules 3 TTPsCVE-2026-4021 describes an authentication bypass vulnerability in the Contest Gallery plugin for WordPress, allowing unauthenticated attackers to gain admin access by manipulating the user activation key and using an AJAX login endpoint.
WP Maps WordPress Plugin Time-Based SQL Injection Vulnerability (CVE-2026-2580)
2 rules 1 TTPThe WP Maps WordPress plugin before version 4.9.2 is vulnerable to time-based SQL Injection via the 'orderby' parameter, allowing unauthenticated attackers to extract sensitive information from the database.
Otter Blocks Plugin Purchase Verification Bypass Vulnerability (CVE-2026-2892)
3 rules 1 TTP 1 CVECVE-2026-2892 is a purchase verification bypass vulnerability in the Otter Blocks plugin for WordPress, affecting versions up to 3.1.4, that allows unauthenticated attackers to access restricted content by forging a cookie used for purchase validation.
DirectoryPress WordPress Plugin Vulnerable to SQL Injection (CVE-2026-3489)
2 rules 1 TTP 1 CVEThe DirectoryPress WordPress plugin before 3.6.26 is vulnerable to unauthenticated SQL Injection via the 'packages' parameter, allowing attackers to extract sensitive database information.
Breeze Cache Plugin Arbitrary File Upload Vulnerability (CVE-2026-3844)
2 rules 1 TTP 1 CVEThe Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation, potentially leading to remote code execution.
Vertex Addons for Elementor WordPress Plugin Missing Authorization Vulnerability (CVE-2026-4326)
2 rules 1 TTP 1 CVEThe Vertex Addons for Elementor plugin for WordPress up to version 1.6.4 is vulnerable to missing authorization, allowing authenticated attackers with subscriber-level access to install and activate arbitrary plugins.
Jupiter X Core WordPress Plugin Vulnerability Leads to Remote Code Execution
2 rules 1 TTPThe Jupiter X Core plugin for WordPress is vulnerable to remote code execution and stored cross-site scripting due to missing authorization and insufficient file type validation in versions up to 4.14.1, allowing authenticated attackers with subscriber-level access to upload malicious files.
JetEngine WordPress Plugin SQL Injection Vulnerability (CVE-2026-4352)
2 rules 1 TTP 1 CVEThe JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint, allowing unauthenticated attackers to extract sensitive database information.
Career Section WordPress Plugin CSRF Vulnerability Leading to Arbitrary File Deletion
2 rules 1 TTP 1 CVEThe Career Section WordPress plugin, versions 1.6 and earlier, is vulnerable to cross-site request forgery (CSRF), allowing unauthenticated attackers to delete arbitrary files on the server by tricking a site administrator.
ProSolution WP Client Plugin Arbitrary File Upload Vulnerability (CVE-2026-2942)
2 rules 1 TTP 1 CVEThe ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation, allowing unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution.
Prismatic WordPress Plugin Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Prismatic plugin for WordPress versions 3.7.3 and earlier is vulnerable to stored cross-site scripting (XSS) via the 'prismatic_encoded' pseudo-shortcode, allowing unauthenticated attackers to inject arbitrary web scripts into pages.
DSGVO Google Web Fonts GDPR WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-3535)
2 rules 2 TTPs 1 CVEThe DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to unauthenticated arbitrary file upload due to missing file type validation, allowing attackers to upload PHP webshells and achieve remote code execution.
Woocommerce Custom Product Addons Pro Plugin RCE Vulnerability (CVE-2026-4001)
2 rules 1 TTPThe Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution (RCE) due to insufficient sanitization of user-submitted field values, allowing unauthenticated attackers to execute arbitrary code via crafted WCPA text fields.
Amelia Booking WordPress Plugin Insecure Direct Object Reference Vulnerability
2 rules 1 TTPThe Amelia Booking plugin for WordPress versions 9.1.2 and earlier is vulnerable to Insecure Direct Object References (IDOR), allowing authenticated attackers with customer-level permissions or higher to change user passwords and potentially compromise administrator accounts.
Simple Social Media Share Buttons CSRF Vulnerability (CVE-2026-34904)
2 rules 1 TTP 1 CVEA cross-site request forgery (CSRF) vulnerability exists in the Simple Social Media Share Buttons WordPress plugin (versions through 6.2.0), potentially allowing attackers to perform unauthorized actions on behalf of authenticated users.
WP Statistics Plugin Stored XSS Vulnerability (CVE-2026-5231)
2 rules 1 TTP 1 CVEThe WP Statistics WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the 'utm_source' parameter, allowing unauthenticated attackers to inject arbitrary web scripts into admin pages.
JS Help Desk WordPress Plugin Vulnerable to SQL Injection (CVE-2026-2511)
2 rules 1 TTPThe JS Help Desk WordPress plugin versions 3.0.4 and earlier are vulnerable to SQL injection via the `multiformid` parameter in the `storeTickets()` function, allowing unauthenticated attackers to extract sensitive information from the database.
wpForo Forum Plugin Arbitrary File Deletion Vulnerability (CVE-2026-6248)
2 rules 1 TTP 1 CVEThe wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion (CVE-2026-6248) due to insufficient validation and sanitization, allowing authenticated users to delete arbitrary files on the server, potentially leading to remote code execution.
SQL Injection Vulnerability in Form Maker by 10Web WordPress Plugin
2 rules 1 TTP 1 CVEThe Form Maker by 10Web WordPress plugin is vulnerable to SQL Injection via the 'inputs' parameter in versions up to 1.15.42, allowing unauthenticated attackers to extract sensitive information from the database.
WordPress Advanced Members for ACF Plugin Arbitrary File Deletion Vulnerability
2 rules 1 TTP 1 CVEThe Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function, allowing authenticated attackers with Subscriber-level access or higher to delete arbitrary files, potentially leading to remote code execution.
WordPress Drag and Drop Multiple File Upload Plugin Path Traversal Vulnerability
2 rules 1 TTP 1 CVEThe Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files within the 'wp-content' directory readable by the web server process.
Tutor LMS WordPress Plugin Insecure Direct Object Reference (CVE-2026-3360)
2 rules 2 TTPs 1 CVEThe Tutor LMS plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR), allowing unauthenticated attackers to overwrite billing profiles of users with incomplete orders.
Royal Elementor Addons Plugin SSRF Vulnerability
2 rules 1 TTP 1 CVEThe Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) allowing authenticated attackers with Contributor-level access or higher to make arbitrary requests and retrieve sensitive information from internal services.
WordPress Drag and Drop File Upload Plugin Vulnerable to Arbitrary File Upload (CVE-2026-5364)
2 rules 1 TTP 1 CVEThe Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to 1.1.3, allowing unauthenticated attackers to upload arbitrary PHP files by manipulating the file type parameter and exploiting extension sanitization vulnerabilities.
WordPress Profile Builder Pro Plugin PHP Object Injection Vulnerability (CVE-2026-7647)
2 rules 1 TTP 1 CVEAn unauthenticated PHP Object Injection vulnerability exists in the Profile Builder Pro WordPress plugin (versions up to 3.14.5) due to the insecure use of `maybe_unserialize()` on the 'args' POST parameter in the `wppb_request_users_pins_action_callback()` AJAX handler, potentially leading to arbitrary code execution.
WordPress Custom Role Manager Plugin Privilege Escalation via CVE-2026-7106
2 rules 1 TTP 1 CVEHighland Software's Custom Role Manager plugin for WordPress, versions 1.0.0 and earlier, contains a privilege escalation vulnerability (CVE-2026-7106) that allows authenticated users with subscriber-level access to modify user roles due to insufficient authorization checks in the hscrm_save_user_roles() function.
WebPros cPanel & WHM and WP2 Authentication Bypass Vulnerability (CVE-2026-41940)
2 rules 1 TTP 1 CVECVE-2026-41940 is an authentication bypass vulnerability in WebPros cPanel & WHM and WP2 (WordPress Squared) that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
MoreConvert Pro WordPress Plugin Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVEThe MoreConvert Pro plugin for WordPress versions 1.9.14 and earlier is vulnerable to authentication bypass due to improper handling of guest waitlist verification tokens, allowing unauthenticated attackers to potentially gain administrative access.
LatePoint WordPress Plugin Stored XSS Vulnerability
2 rules 1 CVEThe LatePoint WordPress plugin is vulnerable to stored XSS via the booking_form_page_url parameter, allowing unauthenticated attackers to inject arbitrary web scripts in pages that execute when a user accesses the injected page.
Gravity Forms Plugin Unauthenticated Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Gravity Forms plugin for WordPress is vulnerable to unauthenticated stored cross-site scripting (XSS) in versions up to 2.10.0, allowing attackers to inject arbitrary JavaScript code into the product name field within repeater fields, which executes when an administrator views the affected entry.
Geeky Bot WordPress Plugin Missing Authorization Vulnerability Leads to Remote Code Execution
2 rules 3 TTPs 1 CVEThe Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to 1.2.2, allowing unauthenticated attackers to perform arbitrary plugin installation and achieve remote code execution by exploiting a nopriv AJAX route and uploading malicious ZIP files.
Easy Appointments WordPress Plugin Sensitive Data Exposure
2 rules 1 TTP 1 CVEThe Easy Appointments WordPress plugin through version 3.12.21 exposes sensitive customer appointment data, including names, emails, phone numbers, and IP addresses, due to an improperly secured REST API endpoint.
Compromised WordPress Plugin 'Accordion and Accordion Slider' Delivers Backdoor
2 rules 2 TTPs 1 CVEA malicious actor injected a backdoor into the WordPress 'Accordion and Accordion Slider' plugin version 1.4.6 after purchasing it, allowing for persistence and spam injection.
Betheme WordPress Theme Arbitrary File Upload Vulnerability
2 rules 1 TTP 1 CVEThe Betheme theme for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level privileges or higher to upload arbitrary files, including PHP, leading to remote code execution.
ARMember WordPress Plugin Vulnerable to Time-Based Blind SQL Injection (CVE-2026-7649)
2 rules 1 TTP 1 CVEA time-based blind SQL Injection vulnerability exists in the ARMember WordPress plugin (<= 4.0.60) due to insufficient input sanitization of the 'orderby' parameter, allowing unauthenticated attackers to extract sensitive database information.
WP-Optimize Plugin Vulnerable to Arbitrary File Deletion
2 rules 2 TTPs 1 CVEThe WP-Optimize plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with author-level access or higher to delete arbitrary files, potentially leading to remote code execution.
Gravity Forms Plugin Unauthenticated Stored XSS Vulnerability
2 rules 1 CVEThe Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) in versions up to and including 2.10.0, allowing unauthenticated attackers to inject arbitrary web scripts via form submissions that execute when an administrator views the entry detail page.
Download Monitor WordPress Plugin Insecure Direct Object Reference
2 rules 1 TTPThe Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) allowing unauthenticated attackers to steal paid digital goods by manipulating PayPal transaction tokens to complete arbitrary orders.
WP DSGVO Tools (GDPR) Plugin Vulnerable to Account Destruction (CVE-2026-4283)
2 rules 1 TTP 1 IOCThe WP DSGVO Tools (GDPR) WordPress plugin before version 3.1.39 is vulnerable to unauthenticated account destruction via the `super-unsubscribe` AJAX action, allowing attackers to irreversibly anonymize non-administrator user accounts.
MW WP Form WordPress Plugin Arbitrary File Move/Read Vulnerability (CVE-2026-5436)
2 rules 2 TTPs 1 CVEThe MW WP Form plugin for WordPress is vulnerable to arbitrary file move/read (CVE-2026-5436) due to insufficient validation of the $name parameter, allowing unauthenticated attackers to move arbitrary files, potentially leading to remote code execution.
Livemesh Addons for Elementor Plugin LFI Vulnerability (CVE-2026-1620)
2 rules 1 TTP 1 CVEThe Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion (LFI) due to insufficient sanitization of the template name parameter, allowing authenticated attackers to include and execute arbitrary files on the server.
GeekyBot WordPress Plugin Vulnerable to SQL Injection
2 rules 1 TTP 1 CVEThe GeekyBot WordPress plugin is vulnerable to SQL Injection, allowing unauthenticated attackers to extract sensitive information from the database by manipulating the 'attributekey' parameter.
ExactMetrics WordPress Plugin Vulnerability Leads to Remote Code Execution
2 rules 4 TTPs 1 CVEThe ExactMetrics plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation via a REST API endpoint, potentially leading to remote code execution by authenticated attackers.
Brizy WordPress Plugin Unauthenticated Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) in versions up to and including 2.8.11, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form Leads page due to missing nonce verification and improper handling of file upload fields.
WordPress Redsys Payment Gateway Plugin Vulnerable to Payment Forgery (CVE-2026-5050)
2 rules 1 TTP 1 CVE 1 IOCThe Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to cryptographic signature forgery, allowing unauthenticated attackers to mark pending orders as paid by forging payment callback data in versions up to 7.0.0.
Optimole WordPress Plugin Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Optimole WordPress plugin before version 4.2.3 is vulnerable to stored cross-site scripting (XSS) due to insufficient input sanitization and output escaping on the 's' parameter (srcset descriptor) in the unauthenticated /wp-json/optimole/v1/optimizations REST endpoint, allowing unauthenticated attackers to inject arbitrary web scripts.