Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,187
Critical181
High650
Medium2,332
Reset
Showing 701-720 of 3187 records
Threat Entry Updated 2025-08-29

CVE-2025-7732 - Changeset Plugin

The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers in all versions up to, and including, 2.18.7 due to insufficient input sanitization and output escaping. The plugin’s JavaScript registration handlers read the client‑supplied 'data-video-title' and 'href' attributes, decode HTML entities by default, and pass them directly into DOM sinks without any escaping or validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an…

PLUGIN Changeset

CVE-2025-7732

MEDIUM CVSS 6.4 2025-08-27
Threat Entry Updated 2025-08-25

CVE-2025-8562 - Changeset Plugin

The Custom Query Shortcode plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.4.0 via the 'lens' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of files on the server, which can contain sensitive information.

PLUGIN Changeset

CVE-2025-8562

MEDIUM CVSS 6.5 2025-08-25
Threat Entry Updated 2025-08-25

CVE-2025-8208 - Changeset Plugin

The Spexo Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.0.23 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8208

MEDIUM CVSS 6.4 2025-08-24
Threat Entry Updated 2025-08-25

CVE-2025-7813 - Changeset Plugin

The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Changeset

CVE-2025-7813

HIGH CVSS 7.2 2025-08-23
Threat Entry Updated 2025-08-22

CVE-2025-9331 - Changeset Theme

The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'welcome_notice_import_handler' function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo data into the site.

THEME Changeset

CVE-2025-9331

MEDIUM CVSS 4.3 2025-08-22
Threat Entry Updated 2025-08-25

CVE-2025-8678 - Changeset Plugin

The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via the 'wp_remote_request' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Changeset

CVE-2025-8678

MEDIUM CVSS 5.9 2025-08-22
Threat Entry Updated 2025-08-22

CVE-2025-8064 - Changeset Plugin

The Bible SuperSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘selector_height’ parameter in all versions up to, and including, 6.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8064

MEDIUM CVSS 6.4 2025-08-21
Threat Entry Updated 2025-12-03

CVE-2025-7221 - Changeset Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the give_update_payment_status() function in all versions up to, and including, 4.5.0. This makes it possible for authenticated attackers, with GiveWP Worker-level access and above, to update donations statuses. This ability is not present in the user interface.

PLUGIN Changeset

CVE-2025-7221

MEDIUM CVSS 4.3 2025-08-21
Threat Entry Updated 2025-08-20

CVE-2025-8102 - Changeset Plugin

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing nonce validations in the edd_sendwp_disconnect() and edd_sendwp_remote_install() functions. This makes it possible for unauthenticated attackers to deactivate or download and activate the SendWP plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2025-8102

MEDIUM CVSS 5.4 2025-08-20
Threat Entry Updated 2025-08-20

CVE-2025-9202 - Changeset Theme

The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the ThemeGrill Demo Importer plugin.

THEME Changeset

CVE-2025-9202

MEDIUM CVSS 4.3 2025-08-20
Threat Entry Updated 2025-08-20

CVE-2025-8618 - Changeset Plugin

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8618

MEDIUM CVSS 6.4 2025-08-20
Threat Entry Updated 2025-08-19

CVE-2025-8783 - Changeset Plugin

The Contact Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title’ parameter in all versions up to, and including, 8.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Changeset

CVE-2025-8783

MEDIUM CVSS 4.4 2025-08-19
Threat Entry Updated 2025-08-19

CVE-2025-8567 - Changeset Plugin

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8567

MEDIUM CVSS 6.4 2025-08-19
Threat Entry Updated 2025-08-19

CVE-2025-8723 - Changeset Plugin

The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to inject arbitrary PHP into the codebase, achieving remote code execution.

PLUGIN Changeset

CVE-2025-8723

CRITICAL CVSS 9.8 2025-08-19
Threat Entry Updated 2025-08-19

CVE-2025-7670 - Changeset Plugin

The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in all versions up to, and including, 6.1.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2025-7670

HIGH CVSS 7.5 2025-08-19
Threat Entry Updated 2025-08-19

CVE-2025-8622 - Changeset Plugin

The Flexible Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flexible Maps shortcode in all versions up to, and including, 1.18.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8622

MEDIUM CVSS 6.4 2025-08-19
Threat Entry Updated 2025-08-18

CVE-2025-8878 - Changeset Plugin

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Changeset

CVE-2025-8878

MEDIUM CVSS 6.5 2025-08-16
Threat Entry Updated 2025-08-18

CVE-2025-7499 - Changeset Plugin

The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_response function in all versions up to and including 4.1.1. This makes it possible for unauthenticated attackers to retrieve passwords for password-protected documents as well as the metadata of private and draft documents.

PLUGIN Changeset

CVE-2025-7499

MEDIUM CVSS 5.3 2025-08-16
Threat Entry Updated 2025-08-18

CVE-2025-8898 - Changeset Plugin

The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.0. This is due to the plugin not properly validating a user's capabilities prior to updating a plugin setting or their identity prior to updating their details like email address. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

PLUGIN Changeset

CVE-2025-8898

CRITICAL CVSS 9.8 2025-08-16
Threat Entry Updated 2025-08-18

CVE-2024-12575 - Changeset Plugin

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 5.8.9 via the 'ays_finish_poll' AJAX action. This makes it possible for unauthenticated attackers to retrieve admin email information which is exposed in the poll response.

PLUGIN Changeset

CVE-2024-12575

MEDIUM CVSS 5.3 2025-08-16
Scroll to top