Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,404
Critical198
High720
Medium2,462
Reset
Showing 1121-1140 of 3404 records
Threat Entry Updated 2025-05-12

CVE-2025-3949 - Changeset Plugin

The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'seedprod_lite_get_revisisons' function in all versions up to, and including, 6.18.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the content of arbitrary landing page revisions.

PLUGIN Changeset

CVE-2025-3949

MEDIUM CVSS 4.3 2025-05-09
Threat Entry Updated 2025-06-27

CVE-2025-3811 - Changeset Plugin

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like email through the edit_newdata_customer_callback() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

PLUGIN Changeset

CVE-2025-3811

CRITICAL CVSS 9.8 2025-05-09
Threat Entry Updated 2025-06-27

CVE-2025-3810 - Changeset Plugin

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the edit_profile_data() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses and passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Changeset

CVE-2025-3810

CRITICAL CVSS 9.8 2025-05-09
Threat Entry Updated 2025-06-04

CVE-2025-3862 - Changeset Plugin

Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-3862

MEDIUM CVSS 6.4 2025-05-08
Threat Entry Updated 2025-06-04

CVE-2025-4127 - Changeset Plugin

The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Price Range’ parameter in all versions up to, and including, 2.7.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts that will execute whenever an administrator accesses the plugin settings page.

PLUGIN Changeset

CVE-2025-4127

MEDIUM CVSS 6.4 2025-05-08
Threat Entry Updated 2025-06-04

CVE-2025-3419 - Changeset Plugin

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Changeset

CVE-2025-3419

HIGH CVSS 7.5 2025-05-08
Threat Entry Updated 2025-05-07

CVE-2025-4104 - Changeset Plugin

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset the administrator’s email and password, and elevate their privileges to that of an administrator.

PLUGIN Changeset

CVE-2025-4104

CRITICAL CVSS 9.8 2025-05-07
Threat Entry Updated 2025-07-11

CVE-2024-12120 - Changeset Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-12120

MEDIUM CVSS 5.4 2025-05-07
Threat Entry Updated 2025-05-07

CVE-2025-3766 - Changeset Plugin

The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_tool function in all versions up to, and including, 2.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain a valid nonce that can be used to generate a global unlock key, which can in turn be used to add arbitrary IP address to the plugin allowlist. This can only by exploited on new installations where the site administrator hasn't visited the loginlockdown…

PLUGIN Changeset

CVE-2025-3766

MEDIUM CVSS 5.4 2025-05-07
Threat Entry Updated 2025-05-07

CVE-2025-4054 - Changeset Plugin

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via the search results.

PLUGIN Changeset

CVE-2025-4054

MEDIUM CVSS 6.1 2025-05-07
Threat Entry Updated 2025-05-07

CVE-2025-2821 - Changeset Plugin

The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_rest_permission function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to modify plugin settings, excluding content from search results.

PLUGIN Changeset

CVE-2025-2821

MEDIUM CVSS 5.3 2025-05-07
Threat Entry Updated 2025-05-07

CVE-2025-2011 - Changeset Plugin

The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2025-2011

HIGH CVSS 7.5 2025-05-06
Threat Entry Updated 2025-05-07

CVE-2025-3782 - Changeset Plugin

The Cision Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-3782

MEDIUM CVSS 6.4 2025-05-06
Threat Entry Updated 2025-05-07

CVE-2025-3281 - Changeset Plugin

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation on the 'member_id' user controlled key. This makes it possible for unauthenticated attackers to delete arbitrary user accounts that have registered through the plugin.

PLUGIN Changeset

CVE-2025-3281

MEDIUM CVSS 5.3 2025-05-06
Threat Entry Updated 2025-05-06

CVE-2025-3438 - Changeset Plugin

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of role when registering. This makes it possible for unauthenticated attackers to to register with the 'wcfm_vendor' role, which is a Store Vendor role in the WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress. The vulnerability can only be exploited if the WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin…

PLUGIN Changeset

CVE-2025-3438

MEDIUM CVSS 6.5 2025-05-02
Threat Entry Updated 2025-05-06

CVE-2025-3858 - Changeset Plugin

The Formality plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-3858

MEDIUM CVSS 6.4 2025-05-02
Threat Entry Updated 2025-05-06

CVE-2025-3748 - Changeset Plugin

The Taxonomy Chain Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pn_chain_menu shortcode in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-3748

MEDIUM CVSS 6.4 2025-05-02
Threat Entry Updated 2025-05-06

CVE-2025-3874 - Changeset Plugin

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to lack of randomization of a user controlled key. This makes it possible for unauthenticated attackers to access customer shopping carts and edit product links, add or delete products, and discover coupon codes.

PLUGIN Changeset

CVE-2025-3874

MEDIUM CVSS 6.5 2025-05-01
Threat Entry Updated 2025-05-06

CVE-2025-3890 - Changeset Plugin

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-3890

MEDIUM CVSS 6.4 2025-05-01
Threat Entry Updated 2025-05-06

CVE-2025-3889 - Changeset Plugin

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 via the 'process_payment_data' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the quantity of a product to a negative number, which subtracts the product cost from the total order cost. The attack will only work with Manual Checkout mode, as PayPal and Stripe will not process payments for a negative quantity.

PLUGIN Changeset

CVE-2025-3889

MEDIUM CVSS 5.3 2025-05-01
Scroll to top