Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total70
Critical8
High22
Medium39
Reset
Showing 21-40 of 70 records
Threat Entry Updated 2026-01-20

CVE-2025-22288 - WordPress Core

Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and Optimization wp-smushit allows Path Traversal.This issue affects Smush Image Compression and Optimization: from n/a through

CORE WordPress Core

CVE-2025-22288

MEDIUM CVSS 4.1 2025-11-06
Threat Entry Updated 2026-01-20

CVE-2025-62987 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Stored XSS.This issue affects Builderall Builder for WordPress: from n/a through

CORE WordPress Core

CVE-2025-62987

MEDIUM CVSS 6.5 2025-10-27
Threat Entry Updated 2026-01-20

CVE-2025-62048 - WordPress Core

Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform SmartCrawl smartcrawl-seo.This issue affects SmartCrawl: from n/a through

CORE WordPress Core

CVE-2025-62048

MEDIUM CVSS 5.4 2025-10-22
Threat Entry Updated 2025-09-26

CVE-2025-60156 - WordPress Core

Cross-Site Request Forgery (CSRF) vulnerability in webandprint AR For WordPress allows Upload a Web Shell to a Web Server. This issue affects AR For WordPress: from n/a through 7.98.

CORE WordPress Core

CVE-2025-60156

CRITICAL CVSS 9.6 2025-09-26
Threat Entry Updated 2025-10-01

CVE-2025-58674 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10,…

CORE WordPress Core

CVE-2025-58674

MEDIUM CVSS 5.9 2025-09-23
Threat Entry Updated 2025-10-01

CVE-2025-58246 - WordPress Core

Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it. This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from…

CORE WordPress Core

CVE-2025-58246

MEDIUM CVSS 4.3 2025-09-23
Threat Entry Updated 2025-09-22

CVE-2025-57919 - WordPress Core

Deserialization of Untrusted Data vulnerability in ConveyThis Language Translate Widget for WordPress – ConveyThis allows Object Injection. This issue affects Language Translate Widget for WordPress – ConveyThis: from n/a through 264.

CORE WordPress Core

CVE-2025-57919

HIGH CVSS 7.2 2025-09-22
Threat Entry Updated 2025-09-11

CVE-2025-48101 - WordPress Core

Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: from n/a through 4.1.1.

CORE WordPress Core

CVE-2025-48101

HIGH CVSS 8.8 2025-09-09
Threat Entry Updated 2025-09-05

CVE-2025-58846 - WordPress Core

Cross-Site Request Forgery (CSRF) vulnerability in Dejan Markovic WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule allows Reflected XSS. This issue affects WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule: from n/a through 2020.1.0.

CORE WordPress Core

CVE-2025-58846

HIGH CVSS 7.1 2025-09-05
Threat Entry Updated 2025-07-22

CVE-2025-54352 - WordPress Core

WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.

CORE WordPress Core

CVE-2025-54352

LOW CVSS 3.7 2025-07-21
Threat Entry Updated 2025-07-16

CVE-2025-47554 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress allows Reflected XSS. This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through 11.6.

CORE WordPress Core

CVE-2025-47554

HIGH CVSS 7.1 2025-07-16
Threat Entry Updated 2025-06-17

CVE-2025-48333 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPQuark eForm - WordPress Form Builder allows Reflected XSS. This issue affects eForm - WordPress Form Builder: from n/a through n/a.

CORE WordPress Core

CVE-2025-48333

HIGH CVSS 7.1 2025-06-17
Threat Entry Updated 2025-05-28

CVE-2025-3704 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions Volunteer Sign Up Sheets allows Stored XSS.This issue affects Volunteer Sign Up Sheets: from n/a before 5.5.5. The patch is available exclusively on GitHub at https://github.com/dbarproductions/pta-volunteer-sign-up-sheets , as the vendor encounters difficulties using SVN to deploy to the WordPress.org repository.

CORE WordPress Core

CVE-2025-3704

MEDIUM CVSS 5.9 2025-05-27
Threat Entry Updated 2025-05-23

CVE-2025-47670 - WordPress Core

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register allows PHP Local File Inclusion. This issue affects WordPress Social Login and Register: from n/a through 7.6.10.

CORE WordPress Core

CVE-2025-47670

HIGH CVSS 8.1 2025-05-23
Threat Entry Updated 2025-05-21

CVE-2025-47582 - WordPress Core

Deserialization of Untrusted Data vulnerability in QuantumCloud WPBot Pro Wordpress Chatbot allows Object Injection.This issue affects WPBot Pro Wordpress Chatbot: from n/a through 12.7.0.

CORE WordPress Core

CVE-2025-47582

CRITICAL CVSS 9.8 2025-05-19
Threat Entry Updated 2025-05-19

CVE-2025-47556 - WordPress Core

Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through 11.5.

CORE WordPress Core

CVE-2025-47556

MEDIUM CVSS 5.4 2025-05-16
Threat Entry Updated 2025-04-17

CVE-2025-32520 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Ali Saleem WordPress Health and Server Condition – Integrated with Google Page Speed allows Reflected XSS. This issue affects WordPress Health and Server Condition – Integrated with Google Page Speed: from n/a through 4.1.1.

CORE WordPress Core

CVE-2025-32520

HIGH CVSS 7.1 2025-04-17
Threat Entry Updated 2025-04-11

CVE-2025-32202 - WordPress Core

Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress allows Upload a Web Shell to a Web Server. This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000025.

CORE WordPress Core

CVE-2025-32202

CRITICAL CVSS 9.1 2025-04-10
Threat Entry Updated 2025-04-09

CVE-2025-31035 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Chris WP Editor.md – The Perfect WordPress Markdown Editor allows Stored XSS. This issue affects WP Editor.md – The Perfect WordPress Markdown Editor: from n/a through 10.2.1.

CORE WordPress Core

CVE-2025-31035

MEDIUM CVSS 5.9 2025-04-09
Threat Entry Updated 2025-04-01

CVE-2025-31735 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in C. Johnson Footnotes for WordPress allows Stored XSS. This issue affects Footnotes for WordPress: from n/a through 2016.1230.

CORE WordPress Core

CVE-2025-31735

MEDIUM CVSS 6.5 2025-04-01
Scroll to top