Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,741
Critical953
High3,204
Medium11,339
Reset
Showing 5121-5140 of 15741 records
Threat Entry Updated 2025-08-12

CVE-2025-8314 - Software Issue Manager Plugin

The Software Issue Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg parameter in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Software Issue Manager

CVE-2025-8314

MEDIUM CVSS 6.4 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-8690 - Addi Simple Slider Plugin

The Simple Responsive Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Addi Simple Slider

CVE-2025-8690

MEDIUM CVSS 6.4 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-8688 - Inline Stock Quotes Plugin

The Inline Stock Quotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Inline Stock Quotes

CVE-2025-8688

MEDIUM CVSS 6.4 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-8685 - Wp Chart Generator Plugin

The Wp chart generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpchart shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Chart Generator

CVE-2025-8685

MEDIUM CVSS 6.4 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-8621 - Mosaic Generator Plugin

The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c’ parameter in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mosaic Generator

CVE-2025-8621

MEDIUM CVSS 6.4 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-8568 - Gmap Venturit Plugin

The GMap Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘h’ parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gmap Venturit

CVE-2025-8568

MEDIUM CVSS 6.4 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-8462 - Rt Easy Builder Advanced Addons For Elementor Plugin

The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the social URL parameter in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rt Easy Builder Advanced Addons For Elementor

CVE-2025-8462

MEDIUM CVSS 6.4 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-5391 - Wc Purchase Orders Plugin

The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Wc Purchase Orders

CVE-2025-5391

HIGH CVSS 8.1 2025-08-12
Threat Entry Updated 2025-08-12

CVE-2025-4390 - Wp Private Content Plus Plugin

The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for unauthenticated attackers to extract sensitive data including the content of resticted posts on archive and feed pages.

PLUGIN Wp Private Content Plus

CVE-2025-4390

MEDIUM CVSS 5.3 2025-08-12
Threat Entry Updated 2026-01-09

CVE-2025-7965 - Cbx Restaurant Booking Plugin

The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Cbx Restaurant Booking

CVE-2025-7965

MEDIUM CVSS 4.3 2025-08-11
Threat Entry Updated 2025-08-13

CVE-2025-4796 - Eventin Plugin

The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_item' function. This makes it possible for unauthenticated attackers with contributor-level and above permissions to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

PLUGIN Eventin

CVE-2025-4796

HIGH CVSS 8.8 2025-08-08
Threat Entry Updated 2025-08-08

CVE-2025-6572 - Through 1 Plugin

The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Through 1

CVE-2025-6572

MEDIUM CVSS 5.9 2025-08-08
Threat Entry Updated 2025-08-12

CVE-2025-8620 - Givewp Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id.

PLUGIN Givewp

CVE-2025-8620

MEDIUM CVSS 5.3 2025-08-06
Threat Entry Updated 2025-08-06

CVE-2025-7727 - Gutenverse Plugin

The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun Fact blocks in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenverse

CVE-2025-7727

MEDIUM CVSS 6.4 2025-08-06
Threat Entry Updated 2025-08-12

CVE-2025-7498 - Exclusive Addons For Elementor Plugin

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget in all versions up to, and including, 2.7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Exclusive Addons For Elementor

CVE-2025-7498

MEDIUM CVSS 6.4 2025-08-06
Threat Entry Updated 2025-08-13

CVE-2025-8100 - Element Pack Plugin

The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and including, 8.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2025-8100

MEDIUM CVSS 5.4 2025-08-06
Threat Entry Updated 2025-08-06

CVE-2025-8420 - Request A Quote Form Plugin

The Request a Quote Form plugin for WordPress is vulnerable to Remote Code Execution in version less than, or equal to, 2.5.2 via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called.

PLUGIN Request A Quote Form

CVE-2025-8420

HIGH CVSS 8.1 2025-08-06
Threat Entry Updated 2025-08-06

CVE-2025-7036 - Cleverreach Wp Plugin

The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Cleverreach Wp

CVE-2025-7036

HIGH CVSS 7.5 2025-08-06
Threat Entry Updated 2025-11-26

CVE-2025-7502 - Page Builder Plugin

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2025-7502

MEDIUM CVSS 6.4 2025-08-06
Threat Entry Updated 2025-08-06

CVE-2025-6986 - File Manager Plugin

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 6.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN File Manager

CVE-2025-6986

MEDIUM CVSS 6.5 2025-08-06
Scroll to top