Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,741
Critical953
High3,204
Medium11,339
Reset
Showing 5141-5160 of 15741 records
Threat Entry Updated 2025-08-06

CVE-2025-6690 - Wp Tournament Registration Plugin

The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Tournament Registration

CVE-2025-6690

MEDIUM CVSS 6.4 2025-08-06
Threat Entry Updated 2025-08-06

CVE-2025-6259 - Esri Map View Plugin

The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Esri Map View

CVE-2025-6259

MEDIUM CVSS 6.4 2025-08-06
Threat Entry Updated 2025-08-06

CVE-2025-6256 - Flex Guten Plugin

The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ parameter in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Flex Guten

CVE-2025-6256

MEDIUM CVSS 6.4 2025-08-06
Threat Entry Updated 2025-08-05

CVE-2025-8295 - Employee Directory Plugin

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Employee Directory

CVE-2025-8295

MEDIUM CVSS 6.4 2025-08-05
Threat Entry Updated 2025-08-12

CVE-2025-6207 - Wp Import Export Lite Plugin

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wp Import Export Lite

CVE-2025-6207

HIGH CVSS 7.5 2025-08-05
Threat Entry Updated 2025-08-13

CVE-2025-5061 - Wp Import Export Lite Plugin

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability was partially patched in version 3.9.29.

PLUGIN Wp Import Export Lite

CVE-2025-5061

HIGH CVSS 7.5 2025-08-05
Threat Entry Updated 2025-08-05

CVE-2025-8294 - Download Counter Plugin

The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Download Counter

CVE-2025-8294

MEDIUM CVSS 6.4 2025-08-05
Threat Entry Updated 2025-08-05

CVE-2025-8315 - Wp Easy Contact Plugin

The WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Easy Contact

CVE-2025-8315

MEDIUM CVSS 6.4 2025-08-05
Threat Entry Updated 2025-08-05

CVE-2025-8313 - Campus Directory Plugin

The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Campus Directory

CVE-2025-8313

MEDIUM CVSS 6.4 2025-08-05
Threat Entry Updated 2025-08-05

CVE-2025-7050 - Google Drive Plugin

The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in file metadata in all versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability can be exploited by the lowest authentication level permitted to upload files, including unauthenticated users, once a file upload shortcode is published on a publicly…

PLUGIN Google Drive

CVE-2025-7050

HIGH CVSS 7.2 2025-08-05
Threat Entry Updated 2025-08-04

CVE-2025-7500 - Ocean Social Sharing Plugin

The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ocean Social Sharing

CVE-2025-7500

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8488 - Header Footer Elementor Plugin

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the compatibility option setting.

PLUGIN Header Footer Elementor

CVE-2025-8488

MEDIUM CVSS 4.3 2025-08-02
Threat Entry Updated 2025-08-25

CVE-2025-6722 - Login Security Plugin

The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5 via the bitfire_* directory that automatically gets created and stores potentially sensitive files without any access restrictions. This makes it possible for unauthenticated attackers to extract sensitive data from various files like config.ini, debug.log, and more when directory listing is enabled on the server and the ~/wp-content/plugins/index.php file is missing or ignored.

PLUGIN Login Security

CVE-2025-6722

MEDIUM CVSS 5.3 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8399 - Mmm Unity Loader Plugin

The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mmm Unity Loader

CVE-2025-8399

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8400 - Bee Quick Gallery Plugin

The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bee Quick Gallery

CVE-2025-8400

MEDIUM CVSS 6.1 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8391 - Magic Edge Lite Image Background Remover Plugin

The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Magic Edge Lite Image Background Remover

CVE-2025-8391

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-6832 - Tracking Employee Time Has Never Been Easier Plugin

The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Tracking Employee Time Has Never Been Easier

CVE-2025-6832

MEDIUM CVSS 6.1 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8317 - Custom Word Cloud Plugin

The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘angle’ parameter in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Custom Word Cloud

CVE-2025-8317

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8212 - Medical Addon For Elementor Plugin

The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter widget in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Medical Addon For Elementor

CVE-2025-8212

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-6754 - Seo Metrics Helper Plugin

The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function in versions 1.0.5 through 1.0.15. Because the AJAX action only verifies a nonce, without checking the caller’s capabilities, a subscriber-level user can retrieve the token and then access the custom endpoint to obtain full administrator cookies.

PLUGIN Seo Metrics Helper

CVE-2025-6754

HIGH CVSS 8.8 2025-08-02
Scroll to top