Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,188
Critical181
High650
Medium2,333
Reset
Showing 881-900 of 3188 records
Threat Entry Updated 2025-07-11

CVE-2025-4594 - Changeset Plugin

The Tournamatch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trn-ladder-registration-button' shortcode in all versions up to, and including, 4.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-4594

MEDIUM CVSS 6.4 2025-05-23
Threat Entry Updated 2025-07-17

CVE-2025-4405 - Changeset Plugin

The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-4405

MEDIUM CVSS 4.9 2025-05-22
Threat Entry Updated 2025-07-17

CVE-2025-4419 - Changeset Plugin

The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 via the 'path' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to access arbitrary images with allowed extensions, outside of the originally intended directory.

PLUGIN Changeset

CVE-2025-4419

MEDIUM CVSS 4.3 2025-05-22
Threat Entry Updated 2025-05-21

CVE-2025-4611 - Changeset Plugin

The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-4611

MEDIUM CVSS 6.4 2025-05-21
Threat Entry Updated 2025-05-21

CVE-2024-5878 - Changeset Plugin

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox JavaScript library (version 2.1.5) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-5878

MEDIUM CVSS 6.4 2025-05-20
Threat Entry Updated 2025-06-04

CVE-2025-2892 - Changeset Plugin

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post Meta Description and Canonical URL parameters in all versions up to, and including, 4.8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-2892

MEDIUM CVSS 6.4 2025-05-19
Threat Entry Updated 2025-05-19

CVE-2025-3715 - Changeset Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-3715

MEDIUM CVSS 6.4 2025-05-18
Threat Entry Updated 2025-05-28

CVE-2025-4101 - Changeset Plugin

The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'delete_fpm_product' function in all versions up to, and including, 4.2.22. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary posts, pages, attachments, and products. The vulnerability was partially patched in version 4.2.22.

PLUGIN Changeset

CVE-2025-4101

MEDIUM CVSS 4.3 2025-05-17
Threat Entry Updated 2025-06-04

CVE-2025-4669 - Changeset Plugin

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-4669

MEDIUM CVSS 6.4 2025-05-17
Threat Entry Updated 2025-06-04

CVE-2024-13613 - Changeset Plugin

The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.3 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can contain file attachments included in chat messages. The vulnerability was partially patched in version 3.3.3.

PLUGIN Changeset

CVE-2024-13613

HIGH CVSS 7.5 2025-05-17
Threat Entry Updated 2025-06-04

CVE-2025-3888 - Changeset Plugin

The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versions up to, and including, 4.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the included SVG file.

PLUGIN Changeset

CVE-2025-3888

MEDIUM CVSS 6.4 2025-05-17
Threat Entry Updated 2025-05-16

CVE-2025-4564 - Changeset Plugin

The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation via the 'delpdf' action in all versions up to, and including, 3.18. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Changeset

CVE-2025-4564

CRITICAL CVSS 9.8 2025-05-15
Threat Entry Updated 2025-05-16

CVE-2025-3053 - Changeset Plugin

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.5.07 via the uip_process_form_input() function. This is due to the function taking user supplied inputs to execute arbitrary functions with arbitrary data, and does not have any sort of capability check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary code on the server.

PLUGIN Changeset

CVE-2025-3053

HIGH CVSS 8.8 2025-05-15
Threat Entry Updated 2025-05-16

CVE-2025-3769 - Changeset Plugin

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.92 via the 'view_booking_summary_in_lightbox' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to retrieve appointment details such as customer names and email addresses.

PLUGIN Changeset

CVE-2025-3769

MEDIUM CVSS 5.3 2025-05-14
Threat Entry Updated 2025-08-12

CVE-2025-3623 - Changeset Plugin

The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthenticated to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files.

PLUGIN Changeset

CVE-2025-3623

CRITICAL CVSS 9.1 2025-05-14
Threat Entry Updated 2025-05-13

CVE-2025-4474 - Changeset Plugin

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_function() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the plugin’s 'register' role setting to make new user registrations default to the administrator role, leading to an elevation of privileges to that of an administrator.

PLUGIN Changeset

CVE-2025-4474

HIGH CVSS 8.8 2025-05-13
Threat Entry Updated 2025-05-13

CVE-2025-4473 - Changeset Plugin

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to control where the plugin sends outgoing emails. By pointing SMTP to their own server, attackers could capture password reset emails intended for administrators, and elevate their privileges for full site takeover.

PLUGIN Changeset

CVE-2025-4473

HIGH CVSS 8.8 2025-05-13
Threat Entry Updated 2025-05-13

CVE-2025-3107 - Changeset Plugin

The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versions up to, and including, 4.9.9.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2025-3107

MEDIUM CVSS 6.5 2025-05-13
Threat Entry Updated 2025-05-21

CVE-2025-3878 - Changeset Plugin

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-3878

MEDIUM CVSS 6.4 2025-05-10
Threat Entry Updated 2025-05-21

CVE-2025-3876 - Changeset Plugin

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to impersonate any account by supplying its username or email and elevate their privileges to that of an administrator.

PLUGIN Changeset

CVE-2025-3876

HIGH CVSS 8.8 2025-05-10
Scroll to top