Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14,273
Critical855
High2,814
Medium10,408
Reset
Showing 5221-5240 of 14273 records
Threat Entry Updated 2025-02-24

CVE-2025-27265 - Google Maps for WordPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aaron D. Campbell Google Maps for WordPress allows DOM-Based XSS. This issue affects Google Maps for WordPress: from n/a through 1.0.3.

PLUGIN Google Maps for WordPress

CVE-2025-27265

MEDIUM CVSS 6.5 2025-02-24
Threat Entry Updated 2025-03-27

CVE-2025-1488 - Wpo365 Msgraphmailer Plugin

The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if 1. they can successfully trick them into performing an action and 2. the plugin is activated but not configured.

PLUGIN Wpo365 Msgraphmailer

CVE-2025-1488

MEDIUM CVSS 4.7 2025-02-24
Threat Entry Updated 2025-05-07

CVE-2024-13822 - Totalcontest Plugin

The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Totalcontest

CVE-2024-13822

MEDIUM CVSS 6.1 2025-02-24
Threat Entry Updated 2025-05-07

CVE-2024-13605 - Form Maker By 10web Plugin

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Form Maker By 10web

CVE-2024-13605

MEDIUM CVSS 4.8 2025-02-24
Threat Entry Updated 2025-05-07

CVE-2024-12308 - Before 4 Plugin

The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 4

CVE-2024-12308

MEDIUM CVSS 5.4 2025-02-24
Threat Entry Updated 2025-02-23

CVE-2024-13728 - Easy Paypal Donation Plugin

The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Easy Paypal Donation

CVE-2024-13728

MEDIUM CVSS 6.1 2025-02-23
Threat Entry Updated 2025-02-22

CVE-2025-0957 - SMTP for Amazon SES – YaySMTP Plugin

The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN SMTP for Amazon SES – YaySMTP

CVE-2025-0957

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-05

CVE-2025-0953 - Yaysmtp Plugin

The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Yaysmtp

CVE-2025-0953

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-05

CVE-2025-0918 - Yaysmtp Plugin

The SMTP for SendGrid – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Yaysmtp

CVE-2025-0918

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-05

CVE-2024-13869 - Wpvivid Backup Migration Plugin

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload folder prevents…

PLUGIN Wpvivid Backup Migration

CVE-2024-13869

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-06

CVE-2025-1361 - Country Blocker Plugin

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.

PLUGIN Country Blocker

CVE-2025-1361

HIGH CVSS 7.5 2025-02-22
Threat Entry Updated 2025-03-18

CVE-2024-13564 - Rife Elementor Extensions Templates Plugin

The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rife Elementor Extensions Templates

CVE-2024-13564

MEDIUM CVSS 6.4 2025-02-22
Threat Entry Updated 2025-02-22

CVE-2024-13474 - Purolator Edition Plugin

The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Purolator Edition

CVE-2024-13474

HIGH CVSS 7.5 2025-02-22
Threat Entry Updated 2025-03-06

CVE-2024-12038 - Buddyforms Plugin

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buddyforms_nav' shortcode in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Buddyforms

CVE-2024-12038

MEDIUM CVSS 6.4 2025-02-22
Threat Entry Updated 2025-03-07

CVE-2024-12467 - Payment By Redsys Plugin

The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters' parameter in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Payment By Redsys

CVE-2024-12467

MEDIUM CVSS 6.1 2025-02-22
Threat Entry Updated 2025-03-06

CVE-2024-13798 - Comboblocks Plugin

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. This makes it possible for unauthenticated attackers to create new orders for products and mark them as paid without actually completing a payment.

PLUGIN Comboblocks

CVE-2024-13798

MEDIUM CVSS 5.3 2025-02-22
Threat Entry Updated 2025-03-06

CVE-2025-1510 - The Custom Post Type Date Archives Plugin

The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN The Custom Post Type Date Archives

CVE-2025-1510

HIGH CVSS 7.3 2025-02-22
Threat Entry Updated 2025-03-06

CVE-2025-1509 - The Show Me The Cookies Plugin

The The Show Me The Cookies plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN The Show Me The Cookies

CVE-2025-1509

HIGH CVSS 7.3 2025-02-22
Threat Entry Updated 2025-03-11

CVE-2024-13899 - Mambo Joomla Importer Plugin

The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input via the $data parameter in the fImportMenu function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional…

PLUGIN Mambo Joomla Importer

CVE-2024-13899

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-11

CVE-2024-13873 - Wp Job Portal Plugin

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.8 via the deleteUserPhoto() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to remove profile photos from users accounts. Please note that this does not officially delete the file.

PLUGIN Wp Job Portal

CVE-2024-13873

MEDIUM CVSS 4.3 2025-02-22
Scroll to top