Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,581
Critical940
High3,162
Medium11,246
Reset
Showing 3861-3880 of 15581 records
Threat Entry Updated 2025-12-01

CVE-2025-12971 - File Manager Plugin

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'wcp_change_post_folder' function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to move arbitrary folder contents to arbitrary folders.

PLUGIN File Manager

CVE-2025-12971

MEDIUM CVSS 4.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-10476 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate several database fix actions. This only affects sites with premium activated.

PLUGIN Wp Fastest Cache

CVE-2025-10476

MEDIUM CVSS 4.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13381 - Ays Chatgpt Assistant Plugin

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files.

PLUGIN Ays Chatgpt Assistant

CVE-2025-13381

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13378 - Ays Chatgpt Assistant Plugin

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.0 via the ays_chatgpt_pinecone_upsert function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Ays Chatgpt Assistant

CVE-2025-13378

MEDIUM CVSS 6.5 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12584 - Quick View For Woocommerce Plugin

The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX endpoint due to insufficient restrictions on which products can be included. This makes it possible for unauthenticated attackers to extract data from private products that they should not have access to.

PLUGIN Quick View For Woocommerce

CVE-2025-12584

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13536 - Blubrry Powerpress Plugin

The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting execution when validation fails in the 'powerpress_edit_post' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Blubrry Powerpress

CVE-2025-13536

HIGH CVSS 8.8 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13441 - Hide Category By User Role For Woocommerce Plugin

The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This is due to a missing capability check on the admin_init hook that executes wp_cache_flush(). This makes it possible for unauthenticated attackers to flush the site's object cache via forged requests, potentially degrading site performance.

PLUGIN Hide Category By User Role For Woocommerce

CVE-2025-13441

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13157 - Qode Wishlist For Woocommerce Plugin

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the 'qode_wishlist_for_woocommerce_wishlist_table_item_callback' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to update the public view of arbitrary wishlists.

PLUGIN Qode Wishlist For Woocommerce

CVE-2025-13157

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13525 - Wpdirectorykit Plugin

The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wpdirectorykit

CVE-2025-13525

MEDIUM CVSS 6.1 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12185 - Stafflist Plugin

The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Stafflist

CVE-2025-12185

MEDIUM CVSS 4.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13143 - Social Polls By Opinionstage Plugin

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.12.0. This is due to missing or insufficient nonce validation on the disconnect_account_action function. This makes it possible for unauthenticated attackers to disconnect the site from the Opinion Stage platform integration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Social Polls By Opinionstage

CVE-2025-13143

MEDIUM CVSS 4.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12123 - Customer Reviews Collector For Woocommerce Plugin

The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email-text' parameter in all versions up to, and including, 4.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Customer Reviews Collector For Woocommerce

CVE-2025-12123

MEDIUM CVSS 6.1 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-7820 - Skt Paypal For Woocommerce Plugin

The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 1.4. This is due to the plugin only enforcing client side controls instead of server-side controls when processing payments. This makes it possible for unauthenticated attackers to make confirmed purchases without actually paying for them.

PLUGIN Skt Paypal For Woocommerce

CVE-2025-7820

HIGH CVSS 7.5 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13540 - Tiare Membership Plugin

The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the 'tiare_membership_init_rest_api_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

PLUGIN Tiare Membership

CVE-2025-13540

CRITICAL CVSS 9.8 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13539 - Findall Membership Plugin

The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.4. This is due to the plugin not properly logging in a user with the data that was previously verified through the 'findall_membership_check_facebook_user' and the 'findall_membership_check_google_user' functions. This makes it possible for unauthenticated attackers to log in as administrative users, as long as they have an existing account on the site which can easily be created by default through the temp user functionality, and access to the administrative user's email.

PLUGIN Findall Membership

CVE-2025-13539

CRITICAL CVSS 9.8 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13538 - Findall Listing Plugin

The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the 'findall_listing_user_registration_additional_params' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site. Note: The vulnerability can only be exploited if the FindAll Membership plugin is also activated, because user registration is in that plugin.

PLUGIN Findall Listing

CVE-2025-13538

CRITICAL CVSS 9.8 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12151 - Simple Folio Plugin

The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Folio

CVE-2025-12151

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12713 - Soundslides Plugin

The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Soundslides

CVE-2025-12713

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12712 - Shouty Plugin

The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up to, and including, 0.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shouty

CVE-2025-12712

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12670 - Wp Twitpic Plugin

The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Twitpic

CVE-2025-12670

MEDIUM CVSS 6.4 2025-11-27
Scroll to top