Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,581
Critical940
High3,162
Medium11,246
Reset
Showing 3741-3760 of 15581 records
Threat Entry Updated 2025-12-08

CVE-2025-13896 - Social Feed Gallery Portfolio Plugin

The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [igp-wp] shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Social Feed Gallery Portfolio

CVE-2025-13896

MEDIUM CVSS 6.4 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13863 - Revinsite Plugin

The RevInsite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `token` parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Revinsite

CVE-2025-13863

MEDIUM CVSS 6.4 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13857 - Yet Another Webclap For Wordpress Plugin

The Yet Another WebClap for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter of the webclap_button shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Yet Another Webclap For Wordpress

CVE-2025-13857

MEDIUM CVSS 6.4 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13856 - Extra Post Images Plugin

The Extra Post Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the extra-images shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Extra Post Images

CVE-2025-13856

MEDIUM CVSS 6.4 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13656 - Cute News Ticker Plugin

The Cute News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cute News Ticker

CVE-2025-13656

MEDIUM CVSS 6.4 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13894 - Csv Sumotto Plugin

The CSV Sumotto plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Csv Sumotto

CVE-2025-13894

MEDIUM CVSS 6.1 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13666 - Helloprint Plugin

The Helloprint plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.2. This is due to the plugin registering a public REST API endpoint without implementing authorization checks to verify request authenticity. This makes it possible for unauthenticated attackers to arbitrarily modify WooCommerce order statuses via the /wp-json/helloprint/v1/complete_order_from_helloprint_callback endpoint by providing a valid order reference ID.

PLUGIN Helloprint

CVE-2025-13666

MEDIUM CVSS 5.3 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13626 - Mylco Plugin

The myLCO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Mylco

CVE-2025-13626

MEDIUM CVSS 6.1 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13137 - Woomotiv Plugin

The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woomotiv_limit' parameter in all versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Woomotiv

CVE-2025-13137

MEDIUM CVSS 6.1 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13308 - Application Passwords Plugin

The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' parameter in all versions up to, and including, 0.1.3. This is due to insufficient input sanitization and output escaping on user supplied URLs, which allows javascript: URI schemes to be embedded in the reject_url parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when a user clicks the "No, I do not approve of this connection" button, granted they can successfully trick the victim into performing an action such…

PLUGIN Application Passwords

CVE-2025-13308

MEDIUM CVSS 5.4 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13358 - Codeconfig Accessibility Plugin

The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing authorization checks in versions up to, and including, 1.0.0. This is due to the plugin not performing capability checks in the `Settings::createPage()` function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary published pages on the site via the `ccpcaCreatePage` AJAX action.

PLUGIN Codeconfig Accessibility

CVE-2025-13358

MEDIUM CVSS 5.3 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13629 - Wp Landing Page Plugin

The WP Landing Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing nonce validation on the 'wplp_api_update_text' function. This makes it possible for unauthenticated attackers to update arbitrary post meta via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Landing Page

CVE-2025-13629

MEDIUM CVSS 4.3 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-13309 - Codeconfig Accessibility Plugin

The Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers with subscriber-level access and above to modify the plugin’s global accessibility settings.

PLUGIN Codeconfig Accessibility

CVE-2025-13309

MEDIUM CVSS 4.3 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-12673 - Flex Qr Code Generator Plugin

The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_qr_code() function in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Flex Qr Code Generator

CVE-2025-12673

CRITICAL CVSS 9.8 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-12717 - List Attachments Shortcode Plugin

The List Attachments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_list' parameter in the [list-attachments] shortcode in all versions up to, and including, 0.4.1a due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN List Attachments Shortcode

CVE-2025-12717

MEDIUM CVSS 6.4 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-12715 - Canadian Nutrition Facts Label Plugin

The Canadian Nutrition Facts Label plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'percentage' field in the Nutrition Label custom post type in all versions up to, and including, 3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Canadian Nutrition Facts Label

CVE-2025-12715

MEDIUM CVSS 6.4 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-12721 - G Ffl Cockpit Plugin

The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract information about the server.

PLUGIN G Ffl Cockpit

CVE-2025-12721

MEDIUM CVSS 5.3 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-12720 - G Ffl Cockpit Plugin

The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the handle_enqueue_only() function in all versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to delete arbitrary products.

PLUGIN G Ffl Cockpit

CVE-2025-12720

MEDIUM CVSS 5.3 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-12577 - Listar Directory Listing Plugin

The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/listar/v1/place/save' REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update listing details.

PLUGIN Listar Directory Listing

CVE-2025-12577

MEDIUM CVSS 4.3 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-12574 - Listar Directory Listing Plugin

The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the '/wp-json/listar/v1/place/delete' REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts.

PLUGIN Listar Directory Listing

CVE-2025-12574

MEDIUM CVSS 4.3 2025-12-06
Scroll to top