Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical1
High0
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-06-04

CVE-2025-4578 - File Provider Plugin

The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN File Provider

CVE-2025-4578

CRITICAL CVSS 9.8 2025-06-04
Threat Entry Updated 2025-06-04

CVE-2025-4580 - File Provider Plugin

The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN File Provider

CVE-2025-4580

MEDIUM CVSS 4.3 2025-06-04
Scroll to top