Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,581
Critical940
High3,162
Medium11,246
Reset
Showing 3641-3660 of 15581 records
Threat Entry Updated 2025-12-12

CVE-2025-13660 - Guest Support Plugin

The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. This is due to the plugin exposing a public AJAX endpoint that allows anyone to search for and retrieve user email addresses without any authentication or capability checks. This makes it possible for unauthenticated attackers to enumerate user accounts and extract email addresses via the guest_support_handler=ajax endpoint with the request=get_users parameter.

PLUGIN Guest Support

CVE-2025-13660

MEDIUM CVSS 5.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-12655 - Hippoo Mobile App For Woocommerce Plugin

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up to, and including, 1.7.1. This is due to the REST API endpoint `/wp-json/hippoo/v1/wc/token/save_callback/{token_id}` being registered with `permission_callback => '__return_true'`, which allows unauthenticated access. This makes it possible for unauthenticated attackers to write arbitrary JSON content to the server's publicly accessible upload directory via the vulnerable endpoint.

PLUGIN Hippoo Mobile App For Woocommerce

CVE-2025-12655

MEDIUM CVSS 5.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14356 - Ultimate Addons For Contact Form 7 Plugin

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate and get form submission PDF, when the "PDF Generator" and the "Database" addons are enabled (disabled by default).

PLUGIN Ultimate Addons For Contact Form 7

CVE-2025-14356

MEDIUM CVSS 4.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-12570 - Fancy Product Designer Plugin

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping in the data-to-image.php and pdf-to-image.php files. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Fancy Product Designer

CVE-2025-12570

HIGH CVSS 7.2 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14393 - Security Plugin

The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Security

CVE-2025-14393

MEDIUM CVSS 6.4 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14467 - Wp Job Portal Plugin

The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.3.9. This is due to the plugin explicitly whitelisting the `` tag in its `WPJOBPORTAL_ALLOWED_TAGS` configuration and using insufficient input sanitization when saving job descriptions. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts into job description fields via the job creation/editing interface. These scripts will execute whenever a user accesses an injected page, enabling session hijacking, credential theft, and other malicious…

PLUGIN Wp Job Portal

CVE-2025-14467

MEDIUM CVSS 4.4 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14392 - Simple Theme Changer Plugin

The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_theme_admin, display_method_admin, and set_change_theme_button_name actions actions in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the plugin's settings.

PLUGIN Simple Theme Changer

CVE-2025-14392

MEDIUM CVSS 4.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14344 - Gf Multi Uploader Plugin

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'plupload_ajax_delete_file' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

PLUGIN Gf Multi Uploader

CVE-2025-14344

CRITICAL CVSS 9.8 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14170 - Vimeo Simplegallery Plugin

The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 0.2. This is due to missing authorization checks on the `vimeogallery_admin` function hooked to `admin_menu`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary plugin settings via the `action` parameter.

PLUGIN Vimeo Simplegallery

CVE-2025-14170

MEDIUM CVSS 5.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14166 - Wpmastertoolkit Plugin

The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13.0. This is due to the plugin allowing Author-level users to create and execute arbitrary PHP code through the Code Snippets feature without proper capability checks. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server, leading to remote code execution, privilege escalation, and complete site compromise.

PLUGIN Wpmastertoolkit

CVE-2025-14166

MEDIUM CVSS 5.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14391 - Simple Theme Changer Plugin

The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Simple Theme Changer

CVE-2025-14391

MEDIUM CVSS 4.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14354 - Doubledome Resource Link Library Plugin

The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various unauthorized actions including creating, editing, and deleting resources and categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Doubledome Resource Link Library

CVE-2025-14354

MEDIUM CVSS 4.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14165 - Kirimemail Woocommerce Integration Plugin

The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9. This is due to missing nonce validation on the plugin's settings page. This makes it possible for unauthenticated attackers to modify the plugin's API credentials and integration settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Kirimemail Woocommerce Integration

CVE-2025-14165

MEDIUM CVSS 4.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14143 - Ayo Shortcodes Plugin

The Ayo Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' parameter of the ayo_action shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ayo Shortcodes

CVE-2025-14143

MEDIUM CVSS 6.4 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14138 - Wplg Default Mail From Plugin

The WPLG Default Mail From plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wplg Default Mail From

CVE-2025-14138

MEDIUM CVSS 6.1 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14162 - Bmlt Wordpress Satellite Plugin

The BMLT WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.11.4. This is due to missing nonce validation on the 'BMLTPlugin_create_option' and 'BMLTPlugin_delete_option ' action. This makes it possible for unauthenticated attackers to create new plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Bmlt Wordpress Satellite

CVE-2025-14162

MEDIUM CVSS 4.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14161 - Truefy Embed Plugin

The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the 'truefy_embed_options_update' settings update action. This makes it possible for unauthenticated attackers to update the plugin's settings, including the API key, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Truefy Embed

CVE-2025-14161

MEDIUM CVSS 4.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14160 - Upcoming For Calendly Plugin

The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's Calendly API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Upcoming For Calendly

CVE-2025-14160

MEDIUM CVSS 4.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14158 - Coding Blocks Plugin

The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update plugin settings including the theme configuration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Coding Blocks

CVE-2025-14158

MEDIUM CVSS 4.3 2025-12-12
Threat Entry Updated 2025-12-12

CVE-2025-14064 - Buddytask Plugin

The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple AJAX endpoints in all versions up to, and including, 1.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view, create, modify, and delete task boards belonging to any BuddyPress group, including private and hidden groups they are not members of.

PLUGIN Buddytask

CVE-2025-14064

MEDIUM CVSS 6.5 2025-12-12
Scroll to top