Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,703
Critical951
High3,196
Medium11,318
Reset
Showing 4501-4520 of 15703 records
Threat Entry Updated 2025-10-22

CVE-2025-6833 - Tracking Employee Time Has Never Been Easier Plugin

The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0 via the 'aio_time_clock_lite_js' AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber access and above, to clock other users in and out.

PLUGIN Tracking Employee Time Has Never Been Easier

CVE-2025-6833

MEDIUM CVSS 4.3 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11883 - Responsive Progress Bar Plugin

The Responsive Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rprogress shortcode in versions less than, or equal to, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Responsive Progress Bar

CVE-2025-11883

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11880 - Sm Countdown Widget Plugin

The SM CountDown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's smcountdown shortcode in versions less than, or equal to, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sm Countdown Widget

CVE-2025-11880

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11878 - St Category Wp Plugin

The ST Categories Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's st-categories shortcode in versions less than, or equal to, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN St Category Wp

CVE-2025-11878

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11872 - Material Design Iconic Font Integration Plugin

The Material Design Iconic Font Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdiconic' shortcode in all versions up to, and including, 2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Material Design Iconic Font Integration

CVE-2025-11872

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11870 - Simple Business Data Plugin

The Simple Business Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'simple_business_data' shortcode attributes in all versions up to, and including, 1.0.1. This is due to the plugin not properly sanitizing user input or escaping output when embedding the `type` attribute into the `class` attribute in rendered HTML. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Business Data

CVE-2025-11870

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11867 - Bg Book Publisher Plugin

The Bg Book Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `book_author` post meta, rendered through the `[book_author]` shortcode, in all versions up to, and including, 1.25. This is due to the plugin not properly escaping the meta value before output. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bg Book Publisher

CVE-2025-11867

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11866 - Photographers Galleries Plugin

The Photographers galleries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode attributes (`w`, `h`, `raw_css`, `look`, etc.) in all versions up to, and including, 1.1.8. This is due to the plugin not properly sanitizing user input or escaping output when inserting these values into HTML attributes and inline styles. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Photographers Galleries

CVE-2025-11866

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11834 - Wp Ad Gallery Plugin

The WP AD Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'startindex' parameter of the ad-gallery shortcode in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Ad Gallery

CVE-2025-11834

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11830 - Wp Restaurant Listings Plugin

The WP Restaurant Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter of the restaurant_summary shortcode in all versions up to, and including, 1.0.2. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Restaurant Listings

CVE-2025-11830

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11827 - Oboxmedia Ads Plugin

The Oboxmedia Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_widget' and 'after_widget' parameters of the oboxads-ad-widget shortcode in all versions up to, and including, 1.9.8. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Oboxmedia Ads

CVE-2025-11827

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11825 - Playerzbr Plugin

The Playerzbr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'urlmeta' post meta field in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Playerzbr

CVE-2025-11825

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11824 - Cinza Grid Plugin

The Cinza Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cgrid_skin_content' post meta field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cinza Grid

CVE-2025-11824

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11819 - Wp Thumbnail Plugin

The WP-Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'roboshot' shortcode in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Thumbnail

CVE-2025-11819

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11818 - Wp Responsive Meet The Team Plugin

The WP Responsive Meet The Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wprm_team' shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Responsive Meet The Team

CVE-2025-11818

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11817 - Simple Tableau Viz Plugin

The Simple Tableau Viz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableau' shortcode in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Tableau Viz

CVE-2025-11817

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11813 - Responsive Iframe Googlemap Plugin

The Responsive iframe GoogleMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'responsive_map' shortcode in all versions up to, and including, 1.0.2. This is due to insufficient input sanitization and output escaping on the 'width' and 'height' attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Responsive Iframe Googlemap

CVE-2025-11813

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11811 - Simple Youtube Shortcode Plugin

The Simple Youtube Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embed_youtube' shortcode in all versions up to, and including, 1.1.3. This is due to insufficient input sanitization and output escaping on the 'id' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Youtube Shortcode

CVE-2025-11811

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11810 - Print Button Shortcode Plugin

The Print Button Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'print-button' shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping on the 'target' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Print Button Shortcode

CVE-2025-11810

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11809 - Wp Force Images Download Plugin

The WP-Force Images Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpfid' shortcode in all versions up to, and including, 1.8. This is due to insufficient input sanitization and output escaping on the 'class' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Force Images Download

CVE-2025-11809

MEDIUM CVSS 6.4 2025-10-22
Scroll to top