Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,741
Critical953
High3,204
Medium11,339
Reset
Showing 4841-4860 of 15741 records
Threat Entry Updated 2025-09-22

CVE-2025-10002 - Link Pages Plugin

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection via the export_csv() function in all versions up to, and including, 2.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This may be…

PLUGIN Link Pages

CVE-2025-10002

MEDIUM CVSS 4.9 2025-09-20
Threat Entry Updated 2025-09-22

CVE-2025-10652 - Robcore Netatmo Plugin

The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injection via the ‘module_id’ attribute of the robcore-netatmo shortcode in all versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Robcore Netatmo

CVE-2025-10652

MEDIUM CVSS 6.5 2025-09-20
Threat Entry Updated 2025-09-19

CVE-2025-7665 - Miniorange Firebase Sms Otp Verification Plugin

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premium features must be enabled in order to exploit the vulnerability.

PLUGIN Miniorange Firebase Sms Otp Verification

CVE-2025-7665

HIGH CVSS 8.1 2025-09-19
Threat Entry Updated 2025-09-19

CVE-2025-10647 - Embed Pdf Wpforms Plugin

The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_handler_download_pdf_media function in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Embed Pdf Wpforms

CVE-2025-10647

HIGH CVSS 8.8 2025-09-19
Threat Entry Updated 2025-09-19

CVE-2025-5948 - Service Finder Bookings Plugin

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to claiming a business when using the claim_business AJAX action. This makes it possible for unauthenticated attackers to login as any user including admins. Please note that subscriber privileges or brute-forcing are needed when completing the business takeover. The claim_id is needed to takeover the admin account, but brute-forcing is a practical approach to…

PLUGIN Service Finder Bookings

CVE-2025-5948

CRITICAL CVSS 9.8 2025-09-19
Threat Entry Updated 2025-09-19

CVE-2025-5955 - Service Finder Sms System Plugin

The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugin not verifying a user's phone number before logging them in. This makes it possible for unauthenticated attackers to login as arbitrary users.

PLUGIN Service Finder Sms System

CVE-2025-5955

HIGH CVSS 8.1 2025-09-19
Threat Entry Updated 2025-09-19

CVE-2025-10146 - Download Manager Plugin

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Download Manager

CVE-2025-10146

MEDIUM CVSS 6.1 2025-09-19
Threat Entry Updated 2025-09-19

CVE-2025-8487 - Kubio Ai Page Builder Plugin

The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the kubio-image-hub-install-plugin AJAX action in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the Image Hub plugin.

PLUGIN Kubio Ai Page Builder

CVE-2025-8487

MEDIUM CVSS 5.4 2025-09-19
Threat Entry Updated 2025-09-18

CVE-2025-8565 - Wp Legal Pages Plugin

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the wplp_gdpr_install_plugin_ajax_handler() function in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to install arbitrary repository plugins.

PLUGIN Wp Legal Pages

CVE-2025-8565

HIGH CVSS 8.1 2025-09-18
Threat Entry Updated 2025-09-18

CVE-2025-9992 - Extensions Plugin

The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS field in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Extensions

CVE-2025-9992

MEDIUM CVSS 6.4 2025-09-18
Threat Entry Updated 2025-09-18

CVE-2025-10493 - Chained Quiz Plugin

The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and completion mechanisms due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to hijack and modify other users' quiz attempts by manipulating the chained_completion_id cookie value, allowing them to alter quiz answers, scores, and results of any user. The vulnerability was partially patched in versions 1.3.4 and 1.3.5.

PLUGIN Chained Quiz

CVE-2025-10493

MEDIUM CVSS 5.3 2025-09-18
Threat Entry Updated 2025-12-23

CVE-2025-9083 - Ninja Forms Plugin

The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

PLUGIN Ninja Forms

CVE-2025-9083

CRITICAL CVSS 9.8 2025-09-18
Threat Entry Updated 2025-09-22

CVE-2025-8942 - Wp Hotel Booking Plugin

The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests.

PLUGIN Wp Hotel Booking

CVE-2025-8942

CRITICAL CVSS 9.1 2025-09-18
Threat Entry Updated 2025-09-17

CVE-2025-9565 - Blocksy Companion Plugin

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newsletter_subscribe shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Blocksy Companion

CVE-2025-9565

MEDIUM CVSS 6.4 2025-09-17
Threat Entry Updated 2025-09-17

CVE-2025-9216 - Storeengine Plugin

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Storeengine

CVE-2025-9216

HIGH CVSS 8.8 2025-09-17
Threat Entry Updated 2025-09-17

CVE-2025-9215 - Storeengine Plugin

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the file_download() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Storeengine

CVE-2025-9215

MEDIUM CVSS 6.5 2025-09-17
Threat Entry Updated 2025-09-17

CVE-2025-9203 - Media Player Addons For Elementor Plugin

The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitle_ssize', 'track_title', and 'track_artist_name' parameters in version 1.0.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Media Player Addons For Elementor

CVE-2025-9203

MEDIUM CVSS 6.4 2025-09-17
Threat Entry Updated 2025-09-17

CVE-2025-10058 - Wp Ultimate Csv Importer Plugin

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_function() function in all versions up to, and including, 7.27. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Wp Ultimate Csv Importer

CVE-2025-10058

HIGH CVSS 8.1 2025-09-17
Threat Entry Updated 2025-09-17

CVE-2025-10057 - Wp Ultimate Csv Importer Plugin

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.28. This is due to the write_to_customfile() function writing unfiltered PHP code to a file. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject the customFunction.php file with PHP code that can be accessed to trigger remote code execution.

PLUGIN Wp Ultimate Csv Importer

CVE-2025-10057

HIGH CVSS 8.8 2025-09-17
Scroll to top