Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,581
Critical940
High3,162
Medium11,246
Reset
Showing 3801-3820 of 15581 records
Threat Entry Updated 2025-12-08

CVE-2025-12154 - Auto Thumbnailer Plugin

The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadThumb() function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Auto Thumbnailer

CVE-2025-12154

HIGH CVSS 8.8 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-12153 - Featured Image Via Url Plugin

The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Featured Image Via Url

CVE-2025-12153

HIGH CVSS 8.8 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-12124 - Fitvids For Wordpress Plugin

The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Fitvids For Wordpress

CVE-2025-12124

MEDIUM CVSS 4.4 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-12133 - Eprolo Dropshipping Plugin

The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_eprolo_delete_tracking and wp_ajax_eprolo_save_tracking_data AJAX endpoints in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify and delete tracking data.

PLUGIN Eprolo Dropshipping

CVE-2025-12133

MEDIUM CVSS 4.3 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-12128 - Hide Categories Or Products On Shop Page Plugin

The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7. This is due to missing or incorrect nonce validation on the save_data_hcps() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Hide Categories Or Products On Shop Page

CVE-2025-12128

MEDIUM CVSS 4.3 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-10055 - Time Sheets Plugin

The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to missing or incorrect nonce validation on several endpoints. This makes it possible for unauthenticated attackers to perform a variety of actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Time Sheets

CVE-2025-10055

MEDIUM CVSS 4.3 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-13494 - Ssp Debugging Plugin

The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0. This is due to the plugin storing PHP error logs in a predictable, web-accessible location (wp-content/uploads/ssp-debug/ssp-debug.log) without any access controls. This makes it possible for unauthenticated attackers to view sensitive debugging information including full URLs, client IP addresses, User-Agent strings, WordPress user IDs, and internal filesystem paths.

PLUGIN Ssp Debugging

CVE-2025-13494

MEDIUM CVSS 5.3 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-13362 - Norby Ai Plugin

The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Norby Ai

CVE-2025-13362

MEDIUM CVSS 4.3 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-13313 - Crm Memberships Plugin

The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.5. This is due to missing authorization and authentication checks on the `ntzcrm_changepassword` AJAX action. This makes it possible for unauthenticated attackers to reset arbitrary user passwords and gain unauthorized access to user accounts via the `ntzcrm_changepassword` endpoint, granted they can obtain or enumerate a target user's email address. The plugin also exposes the `ntzcrm_get_users` endpoint without authentication, allowing attackers to enumerate subscriber email addresses, facilitating the exploitation of…

PLUGIN Crm Memberships

CVE-2025-13313

CRITICAL CVSS 9.8 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-13312 - Crm Memberships Plugin

The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_new_tag' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to create arbitrary membership tags and modify CRM configuration that should be restricted to administrators.

PLUGIN Crm Memberships

CVE-2025-13312

MEDIUM CVSS 5.3 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-13006 - Surveyfunnel Lite Plugin

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via several unprotected /wp-json/surveyfunnel/v2/ REST API endpoints. This makes it possible for unauthenticated attackers to extract sensitive data from survey responses.

PLUGIN Surveyfunnel Lite

CVE-2025-13006

MEDIUM CVSS 5.3 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-12417 - Surveyfunnel Lite Plugin

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'surveyfunnel_lite_survey' shortcode in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Surveyfunnel Lite

CVE-2025-12417

MEDIUM CVSS 6.4 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-13066 - Demo Importer Plus Plugin

The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Demo Importer Plus

CVE-2025-13066

HIGH CVSS 8.8 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-12804 - Booking Calendar Plugin

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' shortcode in all versions up to, and including, 10.14.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Booking Calendar

CVE-2025-12804

MEDIUM CVSS 6.4 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-11759 - Restore And Migrate Your Sites With Xcloner Plugin

The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on the Xcloner_Remote_Storage:save() function. This makes it possible for unauthenticated attackers to add or modify an FTP backup configuration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Successful exploitation allows an attacker to set an attacker-controlled FTP site for backup storage and…

PLUGIN Restore And Migrate Your Sites With Xcloner

CVE-2025-11759

MEDIUM CVSS 4.3 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-13543 - Postgallery Plugin

The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class functions in all versions up to, and including, 1.12.5. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Postgallery

CVE-2025-13543

HIGH CVSS 8.8 2025-12-04
Threat Entry Updated 2025-12-04

CVE-2025-12826 - Custom Post Type Ui Plugin

The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to the plugin not verifying that a user has the required capability to perform actions in the "cptui_process_post_type" function. This makes it possible for authenticated attackers, with subscriber level access and above, to add, edit, or delete custom post types in limited situations.

PLUGIN Custom Post Type Ui

CVE-2025-12826

MEDIUM CVSS 4.8 2025-12-04
Threat Entry Updated 2025-12-11

CVE-2025-12782 - Beaver Builder Plugin

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.9.4. This is due to the plugin not properly verifying a user's authorization in the disable() function. This makes it possible for authenticated attackers, with contributor level access and above, to disable the Beaver Builder layout on arbitrary posts and pages, causing content integrity issues and layout disruption on those pages.

PLUGIN Beaver Builder

CVE-2025-12782

MEDIUM CVSS 4.3 2025-12-04
Threat Entry Updated 2025-12-04

CVE-2025-13513 - Clikstats Plugin

The Clik stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Clikstats

CVE-2025-13513

MEDIUM CVSS 6.1 2025-12-04
Threat Entry Updated 2025-12-04

CVE-2025-11727 - Codistoconnect Plugin

The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sync() function in all versions up to, and including, 1.3.65 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Codistoconnect

CVE-2025-11727

HIGH CVSS 7.2 2025-12-04
Scroll to top