Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,703
Critical951
High3,196
Medium11,318
Reset
Showing 4521-4540 of 15703 records
Threat Entry Updated 2025-10-22

CVE-2025-11807 - Mixlr Shortcode Plugin

The Mixlr Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mixlr' shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping on the 'url' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mixlr Shortcode

CVE-2025-11807

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-11804 - Jb News Ticker Plugin

The JB News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the 'jbticker' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Jb News Ticker

CVE-2025-11804

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-10138 - This Or That Plugin

The This-or-That plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'thisorthat' shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN This Or That

CVE-2025-10138

MEDIUM CVSS 6.4 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-10047 - Email Tracker Plugin

The Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emails plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.3.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Email Tracker

CVE-2025-10047

MEDIUM CVSS 4.9 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-12033 - Announcements To The Top Or Bottom Of Your Website Plugin

The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pro_version_activation_code' parameter in all versions up to, and including, 3.0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Announcements To The Top Or Bottom Of Your Website

CVE-2025-12033

MEDIUM CVSS 4.4 2025-10-22
Threat Entry Updated 2025-12-18

CVE-2025-10588 - Api Manager Plugin

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 11.1.2. This is due to missing or incorrect nonce validation on the adminEnableGdprAjax() function. This makes it possible for unauthenticated attackers to modify GDPR settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Api Manager

CVE-2025-10588

MEDIUM CVSS 4.3 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-10570 - Flexible Refund And Return Order For Woocommerce Plugin

The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.38 via the save_refund_request() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to submit refund requests for arbitrary orders that they do not own.

PLUGIN Flexible Refund And Return Order For Woocommerce

CVE-2025-10570

MEDIUM CVSS 4.3 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-10651 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in versions up to, and including, 2.11.22. This is due to insufficient sanitization on the order_mail field and a lack of escaping on output. This makes it possible for authenticated attackers, with Editor-level permissions and above, to inject arbitrary web scripts via the General Setting page that will execute when an administrator accesses the E-mail Setting page.

PLUGIN Welcart E Commerce

CVE-2025-10651

MEDIUM CVSS 5.5 2025-10-22
Threat Entry Updated 2025-10-22

CVE-2025-10638 - Ns Maintenance Mode For Wp Plugin

The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of a site's subscribers containing their name and email address

PLUGIN Ns Maintenance Mode For Wp

CVE-2025-10638

MEDIUM CVSS 5.3 2025-10-22
Threat Entry Updated 2025-10-21

CVE-2025-10916 - Before 1 Plugin

The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

PLUGIN Before 1

CVE-2025-10916

CRITICAL CVSS 9.1 2025-10-21
Threat Entry Updated 2025-10-21

CVE-2025-11536 - Bdthemes Element Pack Lite Plugin

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8.2.5 via the wp_ajax_import_elementor_template action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Bdthemes Element Pack Lite

CVE-2025-11536

MEDIUM CVSS 5.0 2025-10-20
Threat Entry Updated 2025-10-21

CVE-2025-11926 - Related Posts Lite Plugin

The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Related Posts Lite

CVE-2025-11926

MEDIUM CVSS 4.4 2025-10-18
Threat Entry Updated 2025-10-21

CVE-2025-9890 - Theme Editor Plugin

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Theme Editor

CVE-2025-9890

HIGH CVSS 8.8 2025-10-18
Threat Entry Updated 2025-10-21

CVE-2025-11256 - Kognetiks Chatbot Plugin

The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to upload limited safe files and erase conversations.

PLUGIN Kognetiks Chatbot

CVE-2025-11256

MEDIUM CVSS 5.3 2025-10-18
Threat Entry Updated 2025-10-21

CVE-2025-10750 - Embed Power Bi Reports Plugin

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to missing capability checks and authentication verification on the 'testUser' endpoint accessible via the mo_epbr_admin_observer() function hooked on 'init'. This makes it possible for unauthenticated attackers to access sensitive Azure AD user information including personal identifiable information (PII) such as displayName, mail, phones, department, or detailed OAuth error data including Azure AD Application/Client IDs, error codes, trace IDs, and correlation IDs.

PLUGIN Embed Power Bi Reports

CVE-2025-10750

MEDIUM CVSS 5.3 2025-10-18
Threat Entry Updated 2025-10-21

CVE-2025-9562 - Wpcf7 Redirect Plugin

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wpcf7 Redirect

CVE-2025-9562

MEDIUM CVSS 6.4 2025-10-18
Threat Entry Updated 2025-10-21

CVE-2025-11741 - Wpc Smart Quick View For Woocommerce Plugin

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft products that they should not have access to.

PLUGIN Wpc Smart Quick View For Woocommerce

CVE-2025-11741

MEDIUM CVSS 5.3 2025-10-18
Threat Entry Updated 2025-10-21

CVE-2025-11391 - Woocommerce Product Addon Plugin

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image cropper functionality in all versions up to, and including, 33.0.15. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. While the vulnerable code is in the free version, this only affected users with the paid version of the software installed and activated.

PLUGIN Woocommerce Product Addon

CVE-2025-11391

CRITICAL CVSS 9.8 2025-10-18
Threat Entry Updated 2025-10-21

CVE-2025-11691 - Woocommerce Product Addon Plugin

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PPOM_Meta::get_fields_by_id() function in all versions up to, and including, 33.0.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is only exploitable when the Enable Legacy Price Calculations setting is enabled.

PLUGIN Woocommerce Product Addon

CVE-2025-11691

HIGH CVSS 7.5 2025-10-18
Scroll to top