Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,187
Critical181
High650
Medium2,332
Reset
Showing 681-700 of 3187 records
Threat Entry Updated 2025-09-08

CVE-2025-9085 - Changeset Plugin

The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2025-9085

MEDIUM CVSS 4.9 2025-09-06
Threat Entry Updated 2025-09-04

CVE-2025-9519 - Changeset Plugin

The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 via the plugin's shortcodes. This is due to insufficient restriction of shortcode attributes. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.

PLUGIN Changeset

CVE-2025-9519

HIGH CVSS 7.2 2025-09-04
Threat Entry Updated 2025-09-04

CVE-2025-9219 - Changeset Plugin

The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_post_smtp_pro_option_callback' function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable pro extensions.

PLUGIN Changeset

CVE-2025-9219

MEDIUM CVSS 4.3 2025-09-03
Threat Entry Updated 2025-09-04

CVE-2025-9378 - Changeset Plugin

The Vayu Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attributes in the Lottie block in all versions up to, and including, 1.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-9378

MEDIUM CVSS 6.4 2025-09-03
Threat Entry Updated 2025-09-02

CVE-2025-5083 - Changeset Plugin

The Amministrazione Trasparente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Changeset

CVE-2025-5083

MEDIUM CVSS 5.5 2025-08-31
Threat Entry Updated 2025-09-02

CVE-2025-9500 - Changeset Plugin

The TablePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode_debug’ parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-9500

MEDIUM CVSS 6.4 2025-08-30
Threat Entry Updated 2025-09-02

CVE-2025-9499 - Changeset Plugin

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's oceanwp_library shortcode in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-9499

MEDIUM CVSS 6.4 2025-08-30
Threat Entry Updated 2025-12-08

CVE-2024-13342 - Changeset Plugin

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_files_to_order' function in all versions up to, and including, 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files with double extensions on the affected site's server which may make remote code execution possible. This is only exploitable on select instances where the configuration will execute the first extension present.

PLUGIN Changeset

CVE-2024-13342

HIGH CVSS 8.1 2025-08-29
Threat Entry Updated 2025-08-29

CVE-2025-8150 - Changeset Plugin

The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter and Countdown widgets in all versions up to, and including, 2.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8150

MEDIUM CVSS 6.4 2025-08-29
Threat Entry Updated 2025-08-29

CVE-2025-8147 - Changeset Plugin

The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on the lwscache_activatePlugin() function in all versions up to, and including, 2.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate arbitrary whitelisted LWS plugins.

PLUGIN Changeset

CVE-2025-8147

MEDIUM CVSS 4.3 2025-08-29
Threat Entry Updated 2025-08-29

CVE-2025-9376 - Changeset Plugin

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the 'stopbadbots_check_wordpress_logged_in_cookie' function in all versions up to, and including, 11.58. This makes it possible for unauthenticated attackers to bypass blocklists, rate limits, and other plugin functionality.

PLUGIN Changeset

CVE-2025-9376

MEDIUM CVSS 6.5 2025-08-28
Threat Entry Updated 2025-08-29

CVE-2025-8073 - Changeset Plugin

The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8073

MEDIUM CVSS 6.4 2025-08-28
Threat Entry Updated 2025-08-29

CVE-2025-6255 - Changeset Plugin

The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-6255

MEDIUM CVSS 6.4 2025-08-28
Threat Entry Updated 2025-08-29

CVE-2025-7955 - Changeset Plugin

The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes.

PLUGIN Changeset

CVE-2025-7955

CRITICAL CVSS 9.8 2025-08-28
Threat Entry Updated 2025-08-29

CVE-2025-7956 - Changeset Plugin

The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in its AJAX search handler in all versions up to, and including, 4.13.1. This makes it possible for unauthenticated attackers to issue repeated AJAX requests to leak the content of any protected post in rolling 100‑character windows.

PLUGIN Changeset

CVE-2025-7956

MEDIUM CVSS 5.3 2025-08-28
Threat Entry Updated 2025-08-29

CVE-2024-13807 - Changeset Plugin

The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.1.0.5 via the backup functionality due to weak filename structure and lack of protection in the directory. This makes it possible for unauthenticated attackers to extract sensitive data from backups which can include the entire database and site's files.

PLUGIN Changeset

CVE-2024-13807

HIGH CVSS 7.5 2025-08-28
Threat Entry Updated 2025-08-29

CVE-2025-8977 - Changeset Plugin

The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in all versions up to, and including, 3.9.33 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2025-8977

MEDIUM CVSS 6.5 2025-08-28
Threat Entry Updated 2025-08-29

CVE-2025-9346 - Changeset Plugin

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 10.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-9346

MEDIUM CVSS 6.4 2025-08-28
Threat Entry Updated 2025-08-29

CVE-2025-7812 - Changeset Plugin

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.6. This is due to missing or incorrect nonce validation on the adminExport() function. This makes it possible for unauthenticated attackers to update settings and execute remote code when the Server command execution setting is enabled via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2025-7812

HIGH CVSS 8.8 2025-08-28
Threat Entry Updated 2025-12-11

CVE-2025-8897 - Changeset Plugin

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'fl_builder' parameter in all versions up to, and including, 2.9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2025-8897

MEDIUM CVSS 6.1 2025-08-28
Scroll to top