Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form. Join the discussion | CVE Database V5 | 10/02/2026, 05:30:18 UTC Added: 10/02/2026, 05:46:37 UTC |
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled Autoptimize's 'Lazy-load images?' option, the w3-total-cache/w3-total-cache.php file to be present on disk with the plugin disabled, a class named Minify_HTML to be loaded into scope by another plugin, and the malicious comment to be approved by a moderator before the payload renders. Join the discussion | CVE Database V5 | 10/02/2026, 05:30:18 UTC Added: 10/02/2026, 05:46:37 UTC |
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Exploitation requires sending a malicious widgetData payload containing a legacy top-level theme key alongside a non-empty columns array to the /wp-json/sowb/v1/widgets/previews REST endpoint, which bypasses field validation because update_fields() only processes declared form fields. Join the discussion | CVE Database V5 | 10/02/2026, 05:30:17 UTC Added: 10/02/2026, 05:46:37 UTC |
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled. Join the discussion | CVE Database V5 | 10/02/2026, 05:30:17 UTC Added: 10/02/2026, 05:46:37 UTC |
0 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action='update' with register_login_user_id_update='true') and then submit it with user_id set to an administrator's ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts — including administrators — resulting in account takeover and full site compromise. Join the discussion | CVE Database V5 | 10/02/2026, 05:30:17 UTC Added: 10/02/2026, 05:46:37 UTC |
0 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used without validation to attach a file to the form's notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin's External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file. Join the discussion | CVE Database V5 | 10/02/2026, 05:30:15 UTC Added: 10/02/2026, 05:46:37 UTC |
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions up to, and including, 7.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The injected value is propagated through Fusion_Multilingual::set_active_language() and concatenated into a URL by Fusion_Settings::get_setting_link() without applying urlencode(), esc_url(), or esc_attr() before being echoed raw into a double-quoted href attribute in the post editor metabox. Join the discussion | CVE Database V5 | 10/02/2026, 05:30:15 UTC Added: 10/02/2026, 05:46:37 UTC |
0 CTX Feed Pro WordPress plugin versions up to and including 7.6.12 contain a code injection vulnerability due to improper input validation on the 'Feed Config' field. Authenticated users with Administrator-level privileges can exploit this flaw to execute arbitrary PHP code on the server. The vulnerability is identified as CWE-94 and has a CVSS 3.1 score of 7.2, indicating high severity. Join the discussion | CVE Database V5 | 10/02/2026, 04:27:11 UTC Added: 10/02/2026, 04:46:50 UTC |
The Divi Membership WordPress plugin up to version 2.3.0 contains an authentication bypass vulnerability. This flaw allows unauthenticated attackers to impersonate any existing user, including administrators, by exploiting the process_paypal_callback function. The function accepts a base64-encoded GET parameter without proper validation, enabling attackers to set arbitrary user IDs and gain full site control. Join the discussion | CVE Database V5 | 10/02/2026, 04:27:11 UTC Added: 10/02/2026, 04:46:50 UTC |
The Visitor Traffic Real Time Statistics Pro WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in all versions up to and including 11.22. An unauthenticated attacker can exploit this by submitting malicious JavaScript via the page_title parameter in an AJAX action. This script is stored without sanitization and later executed in an administrator's browser when viewing the plugin dashboard, potentially compromising the admin session. Join the discussion | CVE Database V5 | 10/02/2026, 03:38:46 UTC Added: 10/02/2026, 03:46:36 UTC |
Showing 1 to 10 of 142704 results