Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,165
Critical181
High644
Medium2,316
Reset
Showing 321-340 of 3165 records
Threat Entry Updated 2026-01-13

CVE-2025-13457 - Changeset Plugin

The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Square "ccof" (credit card on file) values and leverage this value to potentially make fraudulent charges on the target site.

PLUGIN Changeset

CVE-2025-13457

HIGH CVSS 7.5 2026-01-10
Threat Entry Updated 2026-04-15

CVE-2026-0627 - Changeset Plugin

The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.1.10. This is due to insufficient sanitization of SVG file content that only removes `` tags while allowing other XSS vectors such as event handlers (onload, onerror, onmouseover), foreignObject elements, and SVG animation attributes. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts via malicious SVG file uploads that will execute whenever a user views the uploaded file.

PLUGIN Changeset

CVE-2026-0627

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14937 - Changeset Plugin

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/forms/update_field' AJAX action in all versions up to, and including, 3.28.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-14937

HIGH CVSS 7.2 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14657 - Changeset Plugin

The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including, 4.0.51. This makes it possible for unauthenticated attackers to modify plugin settings. Furthermore, due to insufficient input sanitization and output escaping on the 'etn_primary_color' setting, this enables unauthenticated attackers to inject arbitrary web scripts that will execute whenever a user accesses a page where Eventin styles are loaded.

PLUGIN Changeset

CVE-2025-14657

HIGH CVSS 7.2 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13935 - Changeset Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completion in all versions up to, and including, 3.9.2. This is due to missing enrollment verification in the 'mark_course_complete' function. This makes it possible for authenticated attackers, with subscriber level access and above, to mark any course as completed.

PLUGIN Changeset

CVE-2025-13935

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13934 - Changeset Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollment in all versions up to, and including, 3.9.3. This is due to a missing capability check and purchasability validation in the `course_enrollment()` AJAX handler. This makes it possible for authenticated attackers, with subscriber level access and above, to enroll themselves in any course without going through the proper purchase flow.

PLUGIN Changeset

CVE-2025-13934

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13753 - Changeset Plugin

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect authorization check on the save_table() function in all versions up to, and including, 2.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new wptb-table posts.

PLUGIN Changeset

CVE-2025-13753

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13628 - Changeset Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability check on the 'bulk_action_handler' and 'coupon_permanent_delete' functions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with subscriber level access and above, to delete, activate, deactivate, or trash arbitrary coupons.

PLUGIN Changeset

CVE-2025-13628

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-15057 - Changeset Plugin

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) parameter in all versions up to, and including, 5.3.3. This is due to insufficient input sanitization and output escaping on the fingerprint value stored in the database. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the Real-time Access Log report.

PLUGIN Changeset

CVE-2025-15057

HIGH CVSS 7.2 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-15055 - Changeset Plugin

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' parameters in all versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the Recent Custom Events report.

PLUGIN Changeset

CVE-2025-15055

HIGH CVSS 7.2 2026-01-09
Threat Entry Updated 2026-04-15

CVE-2026-0563 - Changeset Plugin

The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpgsv_map' shortcode in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2026-0563

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-15019 - Changeset Plugin

The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bialty_cs_alt' post meta in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the post editor.

PLUGIN Changeset

CVE-2025-15019

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14736 - Changeset Plugin

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.25. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field.

PLUGIN Changeset

CVE-2025-14736

CRITICAL CVSS 9.8 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14893 - Changeset Plugin

The IndieWeb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Telephone' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-14893

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14782 - Changeset Plugin

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.49.1 via the 'listen_for_csv_export' function. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with access to the Forminator dashboard, to export sensitive form submission data including personally identifiable information.

PLUGIN Changeset

CVE-2025-14782

MEDIUM CVSS 5.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14720 - Changeset Plugin

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending of queued notifications (emails/SMS/WhatsApp), and access debug information among other things.

PLUGIN Changeset

CVE-2025-14720

MEDIUM CVSS 5.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13749 - Changeset Plugin

The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing nonce validation on the "wbcr_upm_change_flag" function. This makes it possible for unauthenticated attackers to disable plugin/theme update notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2025-13749

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14436 - Changeset Plugin

The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’ parameter in all versions up to, and including, 4.0.49 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-14436

HIGH CVSS 7.2 2026-01-08
Threat Entry Updated 2026-01-08

CVE-2025-14984 - Changeset Plugin

The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.3.2. This is due to the plugin's framework component adding SVG to the allowed MIME types via the upload_mimes filter without implementing any sanitization of SVG file contents. This makes it possible for authenticated attackers, with Author-level access and above, to upload SVG files containing malicious JavaScript that executes when the file is viewed, leading to arbitrary JavaScript execution in victims' browsers.

PLUGIN Changeset

CVE-2025-14984

MEDIUM CVSS 6.4 2026-01-08
Threat Entry Updated 2026-01-08

CVE-2025-13679 - Changeset Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_order_by_id() function in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate order IDs and exfiltrate sensitive data (PII), such as student name, email address, phone number, and billing address.

PLUGIN Changeset

CVE-2025-13679

MEDIUM CVSS 6.5 2026-01-08
Scroll to top