Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,188
Critical181
High650
Medium2,333
Reset
Showing 901-920 of 3188 records
Threat Entry Updated 2025-05-12

CVE-2025-2944 - Changeset Plugin

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button and Countdown Widgets in all versions up to, and including, 2.6.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-2944

MEDIUM CVSS 6.4 2025-05-10
Threat Entry Updated 2025-05-12

CVE-2025-4206 - Changeset Plugin

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'process_export_delete' and 'process_import_delete' functions in all versions up to, and including, 4.1.1.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Changeset

CVE-2025-4206

HIGH CVSS 7.2 2025-05-09
Threat Entry Updated 2025-05-12

CVE-2025-3897 - Changeset Plugin

The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 via the 'file_get_contents' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The vulnerability can only be exploited if a caching plugin such as W3 Total Cache is installed and activated.

PLUGIN Changeset

CVE-2025-3897

MEDIUM CVSS 5.9 2025-05-09
Threat Entry Updated 2025-05-12

CVE-2025-4403 - Changeset Plugin

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supported_type string and the uploaded filename without enforcing real extension or MIME checks within the upload() function. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Changeset

CVE-2025-4403

CRITICAL CVSS 9.8 2025-05-09
Threat Entry Updated 2025-05-12

CVE-2025-3949 - Changeset Plugin

The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'seedprod_lite_get_revisisons' function in all versions up to, and including, 6.18.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the content of arbitrary landing page revisions.

PLUGIN Changeset

CVE-2025-3949

MEDIUM CVSS 4.3 2025-05-09
Threat Entry Updated 2025-06-27

CVE-2025-3811 - Changeset Plugin

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like email through the edit_newdata_customer_callback() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

PLUGIN Changeset

CVE-2025-3811

CRITICAL CVSS 9.8 2025-05-09
Threat Entry Updated 2025-06-27

CVE-2025-3810 - Changeset Plugin

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the edit_profile_data() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses and passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Changeset

CVE-2025-3810

CRITICAL CVSS 9.8 2025-05-09
Threat Entry Updated 2025-06-04

CVE-2025-3862 - Changeset Plugin

Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-3862

MEDIUM CVSS 6.4 2025-05-08
Threat Entry Updated 2025-06-04

CVE-2025-4127 - Changeset Plugin

The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Price Range’ parameter in all versions up to, and including, 2.7.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts that will execute whenever an administrator accesses the plugin settings page.

PLUGIN Changeset

CVE-2025-4127

MEDIUM CVSS 6.4 2025-05-08
Threat Entry Updated 2025-06-04

CVE-2025-3419 - Changeset Plugin

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Changeset

CVE-2025-3419

HIGH CVSS 7.5 2025-05-08
Threat Entry Updated 2025-05-07

CVE-2025-4104 - Changeset Plugin

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset the administrator’s email and password, and elevate their privileges to that of an administrator.

PLUGIN Changeset

CVE-2025-4104

CRITICAL CVSS 9.8 2025-05-07
Threat Entry Updated 2025-07-11

CVE-2024-12120 - Changeset Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-12120

MEDIUM CVSS 5.4 2025-05-07
Threat Entry Updated 2025-05-07

CVE-2025-3766 - Changeset Plugin

The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_tool function in all versions up to, and including, 2.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain a valid nonce that can be used to generate a global unlock key, which can in turn be used to add arbitrary IP address to the plugin allowlist. This can only by exploited on new installations where the site administrator hasn't visited the loginlockdown…

PLUGIN Changeset

CVE-2025-3766

MEDIUM CVSS 5.4 2025-05-07
Threat Entry Updated 2025-05-07

CVE-2025-4054 - Changeset Plugin

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via the search results.

PLUGIN Changeset

CVE-2025-4054

MEDIUM CVSS 6.1 2025-05-07
Threat Entry Updated 2025-05-07

CVE-2025-2821 - Changeset Plugin

The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_rest_permission function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to modify plugin settings, excluding content from search results.

PLUGIN Changeset

CVE-2025-2821

MEDIUM CVSS 5.3 2025-05-07
Threat Entry Updated 2025-05-07

CVE-2025-2011 - Changeset Plugin

The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2025-2011

HIGH CVSS 7.5 2025-05-06
Threat Entry Updated 2025-05-07

CVE-2025-3782 - Changeset Plugin

The Cision Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-3782

MEDIUM CVSS 6.4 2025-05-06
Threat Entry Updated 2025-05-07

CVE-2025-3281 - Changeset Plugin

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation on the 'member_id' user controlled key. This makes it possible for unauthenticated attackers to delete arbitrary user accounts that have registered through the plugin.

PLUGIN Changeset

CVE-2025-3281

MEDIUM CVSS 5.3 2025-05-06
Threat Entry Updated 2025-05-06

CVE-2025-3438 - Changeset Plugin

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of role when registering. This makes it possible for unauthenticated attackers to to register with the 'wcfm_vendor' role, which is a Store Vendor role in the WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress. The vulnerability can only be exploited if the WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin…

PLUGIN Changeset

CVE-2025-3438

MEDIUM CVSS 6.5 2025-05-02
Threat Entry Updated 2025-05-06

CVE-2025-3858 - Changeset Plugin

The Formality plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-3858

MEDIUM CVSS 6.4 2025-05-02
Scroll to top