Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,581
Critical940
High3,162
Medium11,246
Reset
Showing 3821-3840 of 15581 records
Threat Entry Updated 2025-12-04

CVE-2025-11379 - Webp Express Plugin

The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is due to the plugin not properly randomizing the name of the config file to prevent direct access on NGINX. This makes it possible for unauthenticated attackers to extract configuration data.

PLUGIN Webp Express

CVE-2025-11379

MEDIUM CVSS 5.3 2025-12-04
Threat Entry Updated 2025-12-16

CVE-2025-13390 - Wp Directory Kit Plugin

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.

PLUGIN Wp Directory Kit

CVE-2025-13390

CRITICAL CVSS 10.0 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-13401 - Autoptimize Plugin

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, 3.1.13 due to insufficient input sanitization and output escaping on user-supplied image attributes in the "create_img_preload_tag" function. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Autoptimize

CVE-2025-13401

MEDIUM CVSS 6.4 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-13756 - Fluent Booking Plugin

The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with subscriber level access and above, to import arbitrary calendars and manage them.

PLUGIN Fluent Booking

CVE-2025-13756

MEDIUM CVSS 4.3 2025-12-03
Threat Entry Updated 2025-12-05

CVE-2025-13359 - Taxopress Plugin

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in all versions up to, and including, 3.40.1. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database granted they have metabox…

PLUGIN Taxopress

CVE-2025-13359

MEDIUM CVSS 6.5 2025-12-03
Threat Entry Updated 2025-12-05

CVE-2025-13354 - Taxopress Plugin

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the "taxopress_merge_terms_batch" function. This makes it possible for authenticated attackers, with subscriber level access and above, to merge or delete arbitrary taxonomy terms.

PLUGIN Taxopress

CVE-2025-13354

MEDIUM CVSS 4.3 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-13342 - Frontend Admin By Dynamiapps Plugin

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for unauthenticated attackers to modify critical WordPress options such as users_can_register, default_role, and admin_email via submitting crafted form data to public frontend forms.

PLUGIN Frontend Admin By Dynamiapps

CVE-2025-13342

CRITICAL CVSS 9.8 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-12887 - Post Smtp Plugin

The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin not properly verifying that a user is authorized to update OAuth tokens on the 'handle_gmail_oauth_redirect' function. This makes it possible for authenticated attackers, with subscriber level access and above, to inject invalid or attacker-controlled OAuth credentials.

PLUGIN Post Smtp

CVE-2025-12887

MEDIUM CVSS 5.4 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-13109 - Products Filter Professional For Woocommerce Plugin

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.7.2 via the "woof_add_query" and "woof_remove_query" functions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber level access and above, to insert or remove arbitrary saved search queries into any user's profile, including administrators.

PLUGIN Products Filter Professional For Woocommerce

CVE-2025-13109

MEDIUM CVSS 4.3 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-12358 - Shopengine Elementor Woocommerce Builder Addon Plugin

The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is due to missing nonce validation on the "post_add_to_list" function as well as an incorrect permissions callback in the "Api/init" function. This makes it possible for unauthenticated attackers to add or remove products from a user's wishlist via a forged request granted they can trick a site's user into performing an action such as clicking on a link.

PLUGIN Shopengine Elementor Woocommerce Builder Addon

CVE-2025-12358

MEDIUM CVSS 4.3 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-13486 - Extended Plugin

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.

PLUGIN Extended

CVE-2025-13486

CRITICAL CVSS 9.8 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-12585 - Mxchat Basic Plugin

The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 via upload filenames. This makes it possible for unauthenticated attackers to extract session values that can subsequently be used to access conversation data.

PLUGIN Mxchat Basic

CVE-2025-12585

MEDIUM CVSS 5.3 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-13495 - Fluent Cart Plugin

The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, and including, 1.3.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Fluent Cart

CVE-2025-13495

MEDIUM CVSS 4.9 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-10304 - Cloning Plugin

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the process_status_unlink() function in all versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to delete the back-up progress files and cause a back-up to fail while it is in progress.

PLUGIN Cloning

CVE-2025-10304

MEDIUM CVSS 5.3 2025-12-03
Threat Entry Updated 2025-12-15

CVE-2025-13646 - Modula Image Gallery Plugin

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files with race condition on the affected site's server which may make remote code execution possible.

PLUGIN Modula Image Gallery

CVE-2025-13646

HIGH CVSS 7.5 2025-12-03
Threat Entry Updated 2025-12-15

CVE-2025-13645 - Modula Image Gallery Plugin

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Modula Image Gallery

CVE-2025-13645

HIGH CVSS 7.2 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-13448 - Cssigniter Shortcodes Plugin

The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode attribute in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cssigniter Shortcodes

CVE-2025-13448

MEDIUM CVSS 6.4 2025-12-03
Threat Entry Updated 2025-12-04

CVE-2025-13542 - Designthemes Lms Plugin

The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

PLUGIN Designthemes Lms

CVE-2025-13542

CRITICAL CVSS 9.8 2025-12-02
Threat Entry Updated 2025-12-02

CVE-2025-12630 - Before 1 Plugin

The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options.

PLUGIN Before 1

CVE-2025-12630

MEDIUM CVSS 4.9 2025-12-02
Scroll to top