Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,581
Critical940
High3,162
Medium11,246
Reset
Showing 3961-3980 of 15581 records
Threat Entry Updated 2025-11-21

CVE-2025-12170 - Checkbox Plugin

The Checkbox plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wp_ajax_nopriv_checkbox_clean_log' AJAX endpoint in all versions up to, and including, 2.8.10. This makes it possible for unauthenticated attackers to clear log files.

PLUGIN Checkbox

CVE-2025-12170

MEDIUM CVSS 5.3 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-12138 - Url Image Importer Plugin

The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.0.6. This is due to the plugin relying on a user-controlled Content-Type HTTP header to validate file uploads in the 'uimptr_import_image_from_url()' function which writes the file to the server before performing proper validation. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible via the uploaded…

PLUGIN Url Image Importer

CVE-2025-12138

HIGH CVSS 8.8 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11985 - Realty Portal Plugin

The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'rp_save_property_settings' function in versions 0.1 to 0.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

PLUGIN Realty Portal

CVE-2025-11985

HIGH CVSS 8.8 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-12135 - Wpbookit Plugin

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1.0.6 due to a missing capability check on the save_custome_code() function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wpbookit

CVE-2025-12135

HIGH CVSS 7.2 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-12086 - Return Refund And Exchange For Woocommerce Plugin

The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the 'wps_rma_cancel_return_request' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete other users refund requests.

PLUGIN Return Refund And Exchange For Woocommerce

CVE-2025-12086

MEDIUM CVSS 4.3 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11802 - Bulma Shortcodes Plugin

The Bulma Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' shortcode attribute in the bulma-notification shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bulma Shortcodes

CVE-2025-11802

MEDIUM CVSS 6.4 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11801 - Audiotube Plugin

The AudioTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' shortcode attribute of the 'audiotube' shortcode in all versions up to, and including, 0.0.3. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Audiotube

CVE-2025-11801

MEDIUM CVSS 6.4 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11800 - Surbma Minicrm Shortcode Plugin

The Surbma | MiniCRM Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the 'minicrm' shortcode in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Surbma Minicrm Shortcode

CVE-2025-11800

MEDIUM CVSS 6.4 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11885 - Echbay Admin Security Plugin

The EchBay Admin Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_ebnonce' parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Echbay Admin Security

CVE-2025-11885

MEDIUM CVSS 6.1 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11815 - Uipress Lite Plugin

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the uip_save_site_option() function in all versions up to, and including, 3.5.08. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary plugin settings. Other AJAX actions are also affected.

PLUGIN Uipress Lite

CVE-2025-11815

MEDIUM CVSS 4.3 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11799 - Affiliate Ai Lite Plugin

The Affiliate AI Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'asin' shortcode attribute in the affiai_img shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Affiliate Ai Lite

CVE-2025-11799

MEDIUM CVSS 6.4 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11770 - Brighttalk Wp Shortcode Plugin

The BrightTALK WordPress Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' shortcode attribute in the brighttalk-time shortcode in all versions up to, and including, 2.4.0. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Brighttalk Wp Shortcode

CVE-2025-11770

MEDIUM CVSS 6.4 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11771 - Tokenico Cryptocurrency Token Launchpad Presale Ico Ido Airdrop Plugin

The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'createSaleRecord' function in all versions up to, and including, 2.4.6. This makes it possible for unauthenticated attackers to manipulate presales counters.

PLUGIN Tokenico Cryptocurrency Token Launchpad Presale Ico Ido Airdrop

CVE-2025-11771

MEDIUM CVSS 5.3 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11773 - Tokenico Cryptocurrency Token Launchpad Presale Ico Ido Airdrop Plugin

The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saveDeployedContract' function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the WordPress option `tokenico_deployed_contracts`, poisoning the smart contract addresses displayed.

PLUGIN Tokenico Cryptocurrency Token Launchpad Presale Ico Ido Airdrop

CVE-2025-11773

MEDIUM CVSS 4.3 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11768 - Islamic Phrases Plugin

The Islamic Phrases plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phrases' shortcode attribute in all versions up to, and including, 2.12.2015. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Islamic Phrases

CVE-2025-11768

MEDIUM CVSS 6.4 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11767 - Tips Shortcode Plugin

The Tips Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tip' shortcode in all versions up to, and including, 0.2.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tips Shortcode

CVE-2025-11767

MEDIUM CVSS 6.4 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11765 - Stock Tools Plugin

The Stock Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_height' and 'image_width' shortcode attributes in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Stock Tools

CVE-2025-11765

MEDIUM CVSS 6.4 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-11764 - Shortcodes Bootstrap Plugin

The Shortcodes Bootstrap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in the [notification] shortcode in all versions up to, and including, 1.1. This is due to missing input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shortcodes Bootstrap

CVE-2025-11764

MEDIUM CVSS 6.4 2025-11-21
Threat Entry Updated 2025-11-26

CVE-2025-11456 - Wsdesk Plugin

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the eh_crm_new_ticket_post() function in all versions up to, and including, 3.3.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wsdesk

CVE-2025-11456

CRITICAL CVSS 9.8 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-10938 - Uipress Lite Plugin

The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user data including password hashes, emails, and other user information that could be used for account takeover attacks.

PLUGIN Uipress Lite

CVE-2025-10938

MEDIUM CVSS 6.5 2025-11-21
Scroll to top