Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14,273
Critical855
High2,814
Medium10,408
Reset
Showing 2821-2840 of 14273 records
Threat Entry Updated 2025-11-12

CVE-2025-11999 - Add Multiple Marker Plugin

The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and amm_save_map_api() functions in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to update the map API and reset maps.

PLUGIN Add Multiple Marker

CVE-2025-11999

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11997 - Document Pro Elementor Plugin

The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.9. This is due to the plugin exposing sensitive Algolia API keys through the frontend JavaScript code via wp_localize_script without proper access restrictions. This makes it possible for unauthenticated attackers to view sensitive API keys in the page source, which could be leveraged to make unauthorized API calls to the configured Algolia search service.

PLUGIN Document Pro Elementor

CVE-2025-11997

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-12-22

CVE-2025-11996 - Find Unused Images Plugin

The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() functiosn in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to delete all of a site's attachments.

PLUGIN Find Unused Images

CVE-2025-11996

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12020 - Double The Donation Plugin

The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Double The Donation

CVE-2025-12020

MEDIUM CVSS 4.9 2025-11-11
Threat Entry Updated 2025-12-22

CVE-2025-12019 - Featured Image Plugin

The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Featured Image

CVE-2025-12019

MEDIUM CVSS 4.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11882 - Simple Donate Plugin

The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortcode in versions less than, or equal to, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Donate

CVE-2025-11882

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11988 - Crypto Plugin

The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the crypto_delete_json method with only a publicly-available nonce check. This makes it possible for unauthenticated attackers to delete specific JSON files matching the pattern *_pending.json within the wp-content/uploads/yak/ directory, causing data loss and denial of service for plugin workflows that rely on these artifacts.

PLUGIN Crypto

CVE-2025-11988

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11986 - Crypto Plugin

The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the register and savenft methods with only a publicly-available nonce check and no wallet signature verification. This makes it possible for unauthenticated attackers to set a site-wide global authentication state via a single transient, bypassing all access controls for ALL visitors to the site. The impact is complete bypass of [crypto-block] shortcode restrictions and page-level access controls,…

PLUGIN Crypto

CVE-2025-11986

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11894 - Shelf Planner Plugin

The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to modify several of the plugin's settings like the ServerKey and LicenseKey.

PLUGIN Shelf Planner

CVE-2025-11894

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11891 - Shelf Planner Plugin

The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.0 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

PLUGIN Shelf Planner

CVE-2025-11891

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11886 - Ctl Arcade Lite Plugin

The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'ctl_arcade_lite_page_manage_games' page. This makes it possible for unauthenticated attackers to deactivate and activate arbitrary plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ctl Arcade Lite

CVE-2025-11886

MEDIUM CVSS 4.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11873 - Wp Bbcode Plugin

The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Bbcode

CVE-2025-11873

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11869 - Precise Columns Plugin

The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attribute in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input or escaping output when inserting the wrapper ID into the generated HTML. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Precise Columns

CVE-2025-11869

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11863 - My Geo Posts Free Plugin

The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode in all versions up to, and including, 1.2. This is due to the plugin not properly sanitizing user input or escaping output of the 'default' shortcode attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN My Geo Posts Free

CVE-2025-11863

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11860 - Ot Twitter Feed Plugin

The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in all versions up to, and including, 1.3.1. This is due to the plugin not properly sanitizing user input and output of the 'width' and 'height' parameters. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ot Twitter Feed

CVE-2025-11860

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11859 - Paypal Donation Shortcode Plugin

The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in all versions up to, and including, 0.1. This is due to the plugin not properly sanitizing user input and output of the 'title' and 'text' parameters. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Paypal Donation Shortcode

CVE-2025-11859

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11874 - Slippy Slider Responsive Touch Navigation Slider Plugin

The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slippy-slider' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slippy Slider Responsive Touch Navigation Slider

CVE-2025-11874

MEDIUM CVSS 5.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11856 - Eventbee Ticketing Widget Plugin

The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketwidget' shortcode in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input and output of several parameters. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Eventbee Ticketing Widget

CVE-2025-11856

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11829 - Five9 Live Chat Plugin

The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the [five9-chat] shortcode in all versions up to, and including, 1.1.2. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Five9 Live Chat

CVE-2025-11829

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11828 - Bnm Blocks Plugin

The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribute in the bnm-blocks/featured-posts-1 block in all versions up to, and including, 1.2.3. This is due to insufficient input sanitization and output escaping when using user-supplied values as HTML tag names. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bnm Blocks

CVE-2025-11828

MEDIUM CVSS 6.4 2025-11-11
Scroll to top