Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14,273
Critical855
High2,814
Medium10,408
Reset
Showing 2761-2780 of 14273 records
Threat Entry Updated 2025-11-14

CVE-2025-11769 - Wp Flipper Plugin

The WordPress Content Flipper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bgcolor' shortcode attribute of the 'flipper_front' shortcode in all versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Flipper

CVE-2025-11769

MEDIUM CVSS 6.4 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-11260 - Wp Rest Headless Plugin

The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.15. This is due to the plugin only checking for the existence of the Authorization header in a request when determining if the nonce protection should be bypassed. This makes it possible for unauthenticated attackers to access content they should not have access to.

PLUGIN Wp Rest Headless

CVE-2025-11260

MEDIUM CVSS 5.3 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-12844 - Ai Engine Plugin

The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via deserialization of untrusted input in the 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' functions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an…

PLUGIN Ai Engine

CVE-2025-12844

HIGH CVSS 7.1 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-12681 - Simple Comment Editing Plugin

The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.0 via the 'ajax_get_comment' function. This makes it possible for unauthenticated attackers to extract sensitive data including user IDs, IP addresses, and email addresses.

PLUGIN Simple Comment Editing

CVE-2025-12681

MEDIUM CVSS 5.3 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-12620 - Poll Maker Plugin

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the ‘filterbyauthor’ parameter in all versions up to, and including, 6.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Poll Maker

CVE-2025-12620

MEDIUM CVSS 4.9 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-12891 - Survey Maker Plugin

The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results' AJAX endpoint in all versions up to, and including, 5.1.9.4. This makes it possible for unauthenticated attackers to view all survey submissions.

PLUGIN Survey Maker

CVE-2025-12891

MEDIUM CVSS 5.3 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-12733 - Wp All Import Plugin

The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.9.6. This is due to the use of eval() on unsanitized user-supplied input in the pmxi_if function within helpers/functions.php. This makes it possible for authenticated attackers, with import capabilities (typically administrators), to inject and execute arbitrary PHP code on the server via crafted import templates. This can lead to remote code execution.

PLUGIN Wp All Import

CVE-2025-12733

HIGH CVSS 8.8 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-12979 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' action in all versions up to, and including, 2.11.24. This makes it possible for unauthenticated attackers to access configured payment credentials (ex. PayPal api secret) , as well as business contact details, mail templates, and other operational settings tied to the store.

PLUGIN Welcart E Commerce

CVE-2025-12979

MEDIUM CVSS 5.3 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-12892 - Survey Maker Plugin

The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 5.1.9.4. This makes it possible for unauthenticated attackers to update the ays_survey_maker_upgrade_plugin option.

PLUGIN Survey Maker

CVE-2025-12892

MEDIUM CVSS 5.3 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-12536 - Sureforms Plugin

The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This makes it possible for unauthenticated attackers to extract sensitive data including email notification configurations, which frequently contain vendor-provided CRM/help desk dropbox addresses, CC/BCC recipients, and notification templates that can be abused to inject malicious data into downstream systems.

PLUGIN Sureforms

CVE-2025-12536

MEDIUM CVSS 5.3 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-12089 - Data Tables Generator By Supsystic Plugin

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Data Tables Generator By Supsystic

CVE-2025-12089

MEDIUM CVSS 6.5 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-12366 - Drag And Drop Website Builder Plugin

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.5 via the pagelayer_replace_page function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to replace media files belonging to other users, including administrators.

PLUGIN Drag And Drop Website Builder

CVE-2025-12366

MEDIUM CVSS 4.3 2025-11-13
Threat Entry Updated 2025-11-14

CVE-2025-11923 - Lifterlms Plugin

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalation. This is due to the plugin not properly validating a user's identity prior to allowing them to modify their own role via the REST API. The permission check in the update_item_permissions_check() function returns true when a user updates their own account without verifying the role changes. This makes it possible for authenticated attackers, with student-level access and above, to escalate their privileges to administrator by updating their own roles array via…

PLUGIN Lifterlms

CVE-2025-11923

HIGH CVSS 8.8 2025-11-13
Threat Entry Updated 2025-11-12

CVE-2025-11994 - Email Subscription With Secure Captcha Plugin

The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Email Subscription With Secure Captcha

CVE-2025-11994

HIGH CVSS 7.2 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-11454 - Customize The Mobile Version Without Redirections Plugin

The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable to SQL Injection via the eos_scfm_duplicate_post_as_draft() function in all versions up to, and including, 0.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with COntributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Customize The Mobile Version Without Redirections

CVE-2025-11454

MEDIUM CVSS 6.5 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12903 - Woo Payment Gateway Plugin

The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wc-braintree/v1/3ds/vaulted_nonce REST API endpoint in all versions up to, and including, 3.2.78. This is due to the endpoint being registered with permission_callback set to __return_true and processing user-supplied token IDs without verifying ownership or authentication. This makes it possible for unauthenticated attackers to retrieve payment method nonces for any stored payment token in the system, which can be used to create fraudulent transactions, charge customer credit cards, or…

PLUGIN Woo Payment Gateway

CVE-2025-12903

HIGH CVSS 7.5 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12732 - Wp Ultimate Csv Importer Plugin

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attackers, with Author-level access or higher, to extract sensitive information including OpenAI API keys configured through the plugin's admin interface.

PLUGIN Wp Ultimate Csv Importer

CVE-2025-12732

MEDIUM CVSS 4.3 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12633 - Bookit Plugin

The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API Endpoint in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to connect their Stripe account and receive payments.

PLUGIN Bookit

CVE-2025-12633

HIGH CVSS 7.5 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12018 - Memberfindme Plugin

The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Memberfindme

CVE-2025-12018

MEDIUM CVSS 4.4 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12113 - Bulk Update Alt Texts For Images Plugin

The Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the atgai_delete_api_key() function in all versions up to, and including, 1.8.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the API key connected to the site.

PLUGIN Bulk Update Alt Texts For Images

CVE-2025-12113

MEDIUM CVSS 4.3 2025-11-12
Scroll to top