Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,703
Critical951
High3,196
Medium11,318
Reset
Showing 4481-4500 of 15703 records
Threat Entry Updated 2025-10-27

CVE-2025-11504 - Quickcreator Plugin

The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticated attackers to view the plugin's API key and subsequently use that to perform actions on the site like creating new posts and injecting XSS payloads.

PLUGIN Quickcreator

CVE-2025-11504

HIGH CVSS 7.5 2025-10-24
Threat Entry Updated 2025-10-27

CVE-2025-11257 - Llm Hubspot Blog Import Plugin

The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_save_blogs' AJAX endpoint in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger an import of all Hubspot data.

PLUGIN Llm Hubspot Blog Import

CVE-2025-11257

MEDIUM CVSS 4.3 2025-10-24
Threat Entry Updated 2025-10-27

CVE-2025-11172 - Check Plagiarism Plugin

The Check Plagiarism plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the chk_plag_mine_plugin_wpse10500_admin_action() function in all versions up to, and including, 2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the API key.

PLUGIN Check Plagiarism

CVE-2025-11172

MEDIUM CVSS 4.3 2025-10-24
Threat Entry Updated 2025-10-27

CVE-2025-10902 - Originality Ai Plugin

The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ai_scan_result_remove' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all data in the wp_originalityai_log database table, which can include post titles, scan scores, credits used, and other data.

PLUGIN Originality Ai

CVE-2025-10902

MEDIUM CVSS 4.3 2025-10-24
Threat Entry Updated 2025-10-27

CVE-2025-10748 - Rapidresult Plugin

The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and including, 1.2. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level permissions and above to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Rapidresult

CVE-2025-10748

MEDIUM CVSS 6.5 2025-10-24
Threat Entry Updated 2025-10-27

CVE-2025-10701 - Time Clock Plugin

The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 1.3.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with Time Clock user credentials to inject arbitrary web scripts in pages that will execute whenever a user accesses an affected page.

PLUGIN Time Clock

CVE-2025-10701

MEDIUM CVSS 6.4 2025-10-24
Threat Entry Updated 2025-10-27

CVE-2025-10740 - Exact Links Plugin

The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provided by the API due to a missing capability check on the verifyRequest function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify links.

PLUGIN Exact Links

CVE-2025-10740

MEDIUM CVSS 6.3 2025-10-24
Threat Entry Updated 2025-10-27

CVE-2025-10749 - Microsoft Azure Storage For Wordpress Plugin

The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in all versions up to, and including, 4.5.1. This is due to missing capability checks on the 'azure-storage-media-replace' AJAX action. This makes it possible for authenticated attackers with subscriber-level access and above to delete arbitrary media files from the WordPress Media Library via the replace_attachment parameter granted they can access the nonce which is exposed to all authenticated users.

PLUGIN Microsoft Azure Storage For Wordpress

CVE-2025-10749

MEDIUM CVSS 5.4 2025-10-24
Threat Entry Updated 2025-10-27

CVE-2025-10901 - Originality Ai Plugin

The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ai_get_table' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read all data in the wp_originalityai_log database table, which can include post titles, scan scores, credits used, and other data.

PLUGIN Originality Ai

CVE-2025-10901

MEDIUM CVSS 4.3 2025-10-24
Threat Entry Updated 2025-10-27

CVE-2025-6440 - Woocommerce Designer Pro Plugin

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Woocommerce Designer Pro

CVE-2025-6440

CRITICAL CVSS 9.8 2025-10-24
Threat Entry Updated 2026-01-09

CVE-2025-10874 - Before 3 Plugin

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

PLUGIN Before 3

CVE-2025-10874

MEDIUM CVSS 5.5 2025-10-24
Threat Entry Updated 2026-01-09

CVE-2025-10723 - Before 11 Plugin

The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks

PLUGIN Before 11

CVE-2025-10723

LOW CVSS 2.7 2025-10-24
Threat Entry Updated 2025-10-27

CVE-2025-7730 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter in all versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2025-7730

MEDIUM CVSS 6.4 2025-10-23
Threat Entry Updated 2025-12-19

CVE-2025-8427 - Beaver Builder Plugin

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 2.9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Beaver Builder

CVE-2025-8427

MEDIUM CVSS 6.4 2025-10-23
Threat Entry Updated 2025-10-27

CVE-2025-11128 - Feedzy Rss Feeds Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query information from internal services.

PLUGIN Feedzy Rss Feeds

CVE-2025-11128

MEDIUM CVSS 5.0 2025-10-23
Threat Entry Updated 2025-10-27

CVE-2025-10705 - Mxchat Basic Plugin

The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.4.6. This is due to insufficient validation of user-supplied URLs in the PDF processing functionality. This makes it possible for unauthenticated attackers to make the WordPress server perform HTTP requests to arbitrary destinations via the mxchat_handle_chat_request AJAX action.

PLUGIN Mxchat Basic

CVE-2025-10705

MEDIUM CVSS 5.3 2025-10-23
Threat Entry Updated 2026-01-20

CVE-2025-53422 - WooCommerce Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeWarriors WhatsApp Chat for WordPress and WooCommerce tw-whatsapp-chat-rotator allows Reflected XSS.This issue affects WhatsApp Chat for WordPress and WooCommerce: from n/a through

PLUGIN WooCommerce

CVE-2025-53422

HIGH CVSS 7.1 2025-10-22
Threat Entry Updated 2026-01-20

CVE-2025-49960 - Vulnerability In Leadbi Leadbi Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leadbi LeadBI Plugin for WordPress leadbi allows Stored XSS.This issue affects LeadBI Plugin for WordPress: from n/a through

PLUGIN Vulnerability In Leadbi Leadbi

CVE-2025-49960

MEDIUM CVSS 6.5 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11086 - Wordpress Lms Plugin For Complete Elearning Solution

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.7. This is due to the plugin not properly validating a user's role prior to registering a user via the Social Login addon. This makes it possible for unauthenticated attackers to update their role to Administrator when registering on the site.

PLUGIN Wordpress Lms Plugin For Complete Elearning Solution

CVE-2025-11086

HIGH CVSS 8.1 2025-10-22
Scroll to top