Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,187
Critical181
High650
Medium2,332
Reset
Showing 721-740 of 3187 records
Threat Entry Updated 2025-08-15

CVE-2025-8451 - Changeset Plugin

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘data-gallery-items’ parameter in all versions up to, and including, 6.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8451

MEDIUM CVSS 6.4 2025-08-15
Threat Entry Updated 2025-08-15

CVE-2025-8013 - Changeset Plugin

The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Changeset

CVE-2025-8013

LOW CVSS 3.8 2025-08-15
Threat Entry Updated 2025-08-13

CVE-2025-7384 - Changeset Plugin

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file is deleted.

PLUGIN Changeset

CVE-2025-7384

CRITICAL CVSS 9.8 2025-08-13
Threat Entry Updated 2025-12-18

CVE-2025-8891 - Changeset Theme

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Changeset

CVE-2025-8891

MEDIUM CVSS 4.3 2025-08-13
Threat Entry Updated 2025-08-13

CVE-2025-8491 - Changeset Plugin

The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the nsc_eprm_save_menu() function. This makes it possible for unauthenticated attackers to upload a menu file via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2025-8491

MEDIUM CVSS 4.3 2025-08-13
Threat Entry Updated 2025-08-13

CVE-2025-0818 - Changeset Plugin

Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.

PLUGIN Changeset

CVE-2025-0818

MEDIUM CVSS 6.5 2025-08-13
Threat Entry Updated 2025-08-12

CVE-2025-8418 - Changeset Plugin

The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Arbitrary Plugin Installation in all versions up to, and including, 1.1.30. This is due to missing capability checks on the activated_plugin function. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins on the server which can make remote code execution possible.

PLUGIN Changeset

CVE-2025-8418

HIGH CVSS 8.8 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-8767 - Changeset Plugin

The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16.17 via the 'download_csv_players' and 'download_csv_games' functions. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

PLUGIN Changeset

CVE-2025-8767

MEDIUM CVSS 4.8 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-6253 - Changeset Plugin

The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.3.0 via the prepare_template() function due to a missing capability check and insufficient controls on the filename specified. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Changeset

CVE-2025-6253

HIGH CVSS 7.5 2025-08-12
Threat Entry Updated 2025-08-15

CVE-2025-8081 - Changeset Plugin

The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Changeset

CVE-2025-8081

MEDIUM CVSS 4.9 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-8059 - Changeset Plugin

The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_registration() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to create a new account and assign it the administrator role.

PLUGIN Changeset

CVE-2025-8059

CRITICAL CVSS 9.8 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-8314 - Changeset Plugin

The Software Issue Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg parameter in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8314

MEDIUM CVSS 6.4 2025-08-12
Threat Entry Updated 2025-08-13

CVE-2025-4796 - Changeset Plugin

The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_item' function. This makes it possible for unauthenticated attackers with contributor-level and above permissions to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

PLUGIN Changeset

CVE-2025-4796

HIGH CVSS 8.8 2025-08-08
Threat Entry Updated 2025-08-06

CVE-2025-7727 - Changeset Plugin

The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun Fact blocks in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-7727

MEDIUM CVSS 6.4 2025-08-06
Threat Entry Updated 2025-08-05

CVE-2025-8295 - Changeset Plugin

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8295

MEDIUM CVSS 6.4 2025-08-05
Threat Entry Updated 2025-08-12

CVE-2025-6207 - Changeset Plugin

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Changeset

CVE-2025-6207

HIGH CVSS 7.5 2025-08-05
Threat Entry Updated 2025-08-13

CVE-2025-5061 - Changeset Plugin

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability was partially patched in version 3.9.29.

PLUGIN Changeset

CVE-2025-5061

HIGH CVSS 7.5 2025-08-05
Threat Entry Updated 2025-08-05

CVE-2025-8294 - Changeset Plugin

The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8294

MEDIUM CVSS 6.4 2025-08-05
Threat Entry Updated 2025-08-05

CVE-2025-8315 - Changeset Plugin

The WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8315

MEDIUM CVSS 6.4 2025-08-05
Threat Entry Updated 2025-08-05

CVE-2025-8313 - Changeset Plugin

The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-8313

MEDIUM CVSS 6.4 2025-08-05
Scroll to top