Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,193
Critical182
High650
Medium2,337
Reset
Showing 1141-1160 of 3193 records
Threat Entry Updated 2025-02-28

CVE-2025-1262 - Changeset Plugin

The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it possible for unauthenticated attackers to bypass the Built-in Math Captcha Verification.

PLUGIN Changeset

CVE-2025-1262

MEDIUM CVSS 5.3 2025-02-25
Threat Entry Updated 2025-02-28

CVE-2024-13494 - Changeset Plugin

The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the 'wfu_file_details' function. This makes it possible for unauthenticated attackers to modify user data details associated with uploaded files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2024-13494

MEDIUM CVSS 4.3 2025-02-25
Threat Entry Updated 2025-02-28

CVE-2025-1128 - Changeset Plugin

The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including, 3.0.9.4. This makes it possible for unauthenticated attackers to upload, read, and delete arbitrary files on the affected site's server which may make remote code execution, sensitive information disclosure, or a site takeover possible.

PLUGIN Changeset

CVE-2025-1128

CRITICAL CVSS 9.8 2025-02-25
Threat Entry Updated 2025-02-28

CVE-2025-1063 - Changeset Plugin

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.4 via the rtcl_taxonomy_settings_export function. This makes it possible for unauthenticated attackers to extract sensitive data including API keys and tokens.

PLUGIN Changeset

CVE-2025-1063

MEDIUM CVSS 5.3 2025-02-25
Threat Entry Updated 2025-03-27

CVE-2025-1488 - Changeset Plugin

The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if 1. they can successfully trick them into performing an action and 2. the plugin is activated but not configured.

PLUGIN Changeset

CVE-2025-1488

MEDIUM CVSS 4.7 2025-02-24
Threat Entry Updated 2025-02-22

CVE-2025-0957 - Changeset Plugin

The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-0957

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-05

CVE-2025-0953 - Changeset Plugin

The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-0953

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-05

CVE-2025-0918 - Changeset Plugin

The SMTP for SendGrid – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-0918

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-05

CVE-2024-13869 - Changeset Plugin

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload folder prevents…

PLUGIN Changeset

CVE-2024-13869

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-06

CVE-2025-1361 - Changeset Plugin

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.

PLUGIN Changeset

CVE-2025-1361

HIGH CVSS 7.5 2025-02-22
Threat Entry Updated 2025-03-18

CVE-2024-13564 - Changeset Plugin

The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-13564

MEDIUM CVSS 6.4 2025-02-22
Threat Entry Updated 2025-03-06

CVE-2024-12038 - Changeset Plugin

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buddyforms_nav' shortcode in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-12038

MEDIUM CVSS 6.4 2025-02-22
Threat Entry Updated 2025-03-11

CVE-2024-13873 - Changeset Plugin

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.8 via the deleteUserPhoto() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to remove profile photos from users accounts. Please note that this does not officially delete the file.

PLUGIN Changeset

CVE-2024-13873

MEDIUM CVSS 4.3 2025-02-22
Threat Entry Updated 2025-02-24

CVE-2024-10222 - Changeset Plugin

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to upload SVG files can be extended to authors.

PLUGIN Changeset

CVE-2024-10222

MEDIUM CVSS 6.4 2025-02-21
Threat Entry Updated 2025-02-25

CVE-2024-13713 - Changeset Plugin

The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2024-13713

MEDIUM CVSS 6.5 2025-02-21
Threat Entry Updated 2025-02-24

CVE-2025-1489 - Changeset Plugin

The WP-Appbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's appbox shortcode in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-1489

MEDIUM CVSS 6.4 2025-02-21
Threat Entry Updated 2025-02-25

CVE-2024-13900 - Changeset Plugin

The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject PHP Code in multisite environments.

PLUGIN Changeset

CVE-2024-13900

MEDIUM CVSS 4.1 2025-02-21
Threat Entry Updated 2025-02-25

CVE-2024-13353 - Changeset Plugin

The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.4 via several widgets. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be…

PLUGIN Changeset

CVE-2024-13353

HIGH CVSS 8.8 2025-02-21
Threat Entry Updated 2025-02-25

CVE-2024-12276 - Changeset Plugin

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with access to upload files and manage filenames through a third-party plugin like a File Manager, to append additional SQL queries into already existing queries that can be used to…

PLUGIN Changeset

CVE-2024-12276

MEDIUM CVSS 5.3 2025-02-21
Threat Entry Updated 2025-02-25

CVE-2025-1410 - Changeset Plugin

The Events Calendar Made Simple – Pie Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's piecal shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-1410

MEDIUM CVSS 6.4 2025-02-21
Scroll to top