Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 41-60 of 837 records
Threat Entry Updated 2026-01-09

CVE-2025-12061 - Before 1 Plugin

The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements

PLUGIN Before 1

CVE-2025-12061

HIGH CVSS 8.6 2025-11-26
Threat Entry Updated 2025-11-14

CVE-2025-10686 - Before 1 Plugin

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

PLUGIN Before 1

CVE-2025-10686

HIGH CVSS 7.2 2025-11-14
Threat Entry Updated 2025-11-06

CVE-2025-10873 - Before 1 Plugin

The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses due to missing authorization on the elementinvader_addons_for_elementor_forms_send_form action.

PLUGIN Before 1

CVE-2025-10873

MEDIUM CVSS 5.3 2025-11-05
Threat Entry Updated 2026-01-09

CVE-2025-11191 - Before 1 Plugin

The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.

PLUGIN Before 1

CVE-2025-11191

MEDIUM CVSS 5.3 2025-10-31
Threat Entry Updated 2025-10-21

CVE-2025-10916 - Before 1 Plugin

The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

PLUGIN Before 1

CVE-2025-10916

CRITICAL CVSS 9.1 2025-10-21
Threat Entry Updated 2025-10-02

CVE-2025-9512 - Before 1 Plugin

The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modifications, making it possible for unauthenticated attackers to conduct Stored XSS attacks via post comments.

PLUGIN Before 1

CVE-2025-9512

MEDIUM CVSS 6.1 2025-10-01
Threat Entry Updated 2025-11-13

CVE-2024-5200 - Before 1 Plugin

The Postie WordPress plugin before 1.9.71 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-5200

MEDIUM CVSS 4.8 2025-09-29
Threat Entry Updated 2025-11-13

CVE-2025-8282 - Before 1 Plugin

The SureForms WordPress plugin before 1.9.1 does not sanitise and escape some parameters when outputing them in the page, which could allow admin and above users to perform Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2025-8282

LOW CVSS 3.5 2025-09-23
Threat Entry Updated 2025-09-11

CVE-2025-9034 - Before 1 Plugin

The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

PLUGIN Before 1

CVE-2025-9034

MEDIUM CVSS 6.1 2025-09-11
Threat Entry Updated 2026-01-30

CVE-2025-8889 - Before 1 Plugin

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

PLUGIN Before 1

CVE-2025-8889

LOW CVSS 3.8 2025-09-09
Threat Entry Updated 2026-01-16

CVE-2025-8046 - Before 1 Plugin

The Injection Guard WordPress plugin before 1.2.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

PLUGIN Before 1

CVE-2025-8046

MEDIUM CVSS 6.1 2025-08-14
Threat Entry Updated 2026-02-20

CVE-2025-7808 - Before 1 Plugin

The WP Shopify WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2025-7808

MEDIUM CVSS 6.1 2025-08-14
Threat Entry Updated 2025-08-14

CVE-2025-3414 - Before 1 Plugin

The Structured Content (JSON-LD) #wpsc WordPress plugin before 1.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2025-3414

MEDIUM CVSS 5.4 2025-08-14
Threat Entry Updated 2025-08-06

CVE-2025-5921 - Before 1 Plugin

The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.

PLUGIN Before 1

CVE-2025-5921

MEDIUM CVSS 5.8 2025-08-01
Threat Entry Updated 2025-07-11

CVE-2025-6236 - Before 1 Plugin

The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2025-6236

MEDIUM CVSS 4.8 2025-07-10
Threat Entry Updated 2025-07-11

CVE-2025-6234 - Before 1 Plugin

The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 1

CVE-2025-6234

MEDIUM CVSS 6.1 2025-07-10
Threat Entry Updated 2025-07-01

CVE-2025-5730 - Before 1 Plugin

The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2025-5730

MEDIUM CVSS 4.3 2025-06-30
Threat Entry Updated 2025-07-11

CVE-2025-5125 - Before 1 Plugin

The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the data-featherlight attribute without sanitizing before using it.

PLUGIN Before 1

CVE-2025-5125

MEDIUM CVSS 4.8 2025-06-20
Threat Entry Updated 2025-07-02

CVE-2025-4955 - Before 1 Plugin

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

PLUGIN Before 1

CVE-2025-4955

MEDIUM CVSS 4.7 2025-06-18
Threat Entry Updated 2025-06-12

CVE-2025-4652 - Before 1 Plugin

The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 1

CVE-2025-4652

MEDIUM CVSS 6.1 2025-06-09
Scroll to top