Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total291
Critical15
High59
Medium208
Reset
Showing 21-40 of 291 records
Threat Entry Updated 2026-01-20

CVE-2025-8944 - Before 4 Theme

The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.

THEME Before 4

CVE-2025-8944

MEDIUM CVSS 4.3 2025-09-05
Threat Entry Updated 2025-06-09

CVE-2025-3951 - Before 4 Plugin

The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.

PLUGIN Before 4

CVE-2025-3951

MEDIUM CVSS 4.1 2025-06-02
Threat Entry Updated 2025-06-04

CVE-2024-9599 - Before 4 Plugin

The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2024-9599

MEDIUM CVSS 5.4 2025-05-15
Threat Entry Updated 2025-06-12

CVE-2024-9236 - Before 4 Plugin

The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2024-9236

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-06-04

CVE-2024-8619 - Before 4 Plugin

The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2024-8619

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-11-13

CVE-2024-8009 - Before 4 Plugin

The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

PLUGIN Before 4

CVE-2024-8009

MEDIUM CVSS 4.3 2025-05-15
Threat Entry Updated 2025-06-05

CVE-2024-6667 - Before 4 Plugin

The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin.

PLUGIN Before 4

CVE-2024-6667

MEDIUM CVSS 6.1 2025-05-15
Threat Entry Updated 2025-06-05

CVE-2024-6665 - Before 4 Plugin

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 4

CVE-2024-6665

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-06-10

CVE-2024-5026 - Before 4 Plugin

The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 4

CVE-2024-5026

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-05-23

CVE-2024-13730 - Before 4 Plugin

The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2024-13730

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-05-23

CVE-2024-13729 - Before 4 Plugin

The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2024-13729

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-05-22

CVE-2024-13128 - Before 4 Plugin

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2024-13128

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-05-22

CVE-2024-13127 - Before 4 Plugin

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2024-13127

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-06-10

CVE-2024-12770 - Before 4 Plugin

The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2024-12770

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-11-13

CVE-2024-0970 - Before 4 Plugin

This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.

PLUGIN Before 4

CVE-2024-0970

MEDIUM CVSS 5.3 2025-05-15
Threat Entry Updated 2025-05-07

CVE-2025-3504 - Before 4 Plugin

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2025-3504

MEDIUM CVSS 4.8 2025-05-01
Threat Entry Updated 2025-05-07

CVE-2025-3503 - Before 4 Plugin

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2025-3503

MEDIUM CVSS 4.8 2025-05-01
Threat Entry Updated 2025-05-07

CVE-2025-3502 - Before 4 Plugin

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2025-3502

MEDIUM CVSS 4.8 2025-05-01
Threat Entry Updated 2025-05-07

CVE-2025-1453 - Before 4 Plugin

The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2025-1453

MEDIUM CVSS 4.8 2025-04-24
Threat Entry Updated 2025-09-30

CVE-2025-2594 - Before 4 Plugin

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.

PLUGIN Before 4

CVE-2025-2594

HIGH CVSS 8.1 2025-04-22
Scroll to top