Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,820
Critical959
High3,226
Medium11,382
Reset
Showing 5621-5640 of 15820 records
Threat Entry Updated 2025-06-09

CVE-2025-5303 - Ltl Freight Quotes Day Ross Edition Plugin

The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day & Ross Edition plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the expiry_date parameter in all versions up to, and including, 1.0.11, 2.2.6 and 2.1.10 respectively, due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ltl Freight Quotes Day Ross Edition

CVE-2025-5303

HIGH CVSS 7.2 2025-06-07
Threat Entry Updated 2025-06-09

CVE-2025-5814 - Profiler What Slowing Down Plugin

The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsd_plugin_control() function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to reactivate previously deactivated plugins after accessing the "Profiler" page.

PLUGIN Profiler What Slowing Down

CVE-2025-5814

MEDIUM CVSS 5.3 2025-06-07
Threat Entry Updated 2025-06-06

CVE-2025-30977 - Chatbots Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chaport Live Chat WP Live Chat + Chatbots Plugin for WordPress – Chaport allows Stored XSS. This issue affects WP Live Chat + Chatbots Plugin for WordPress – Chaport: from n/a through 1.1.5.

PLUGIN Chatbots

CVE-2025-30977

MEDIUM CVSS 5.9 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5239 - Domain For Sale Plugin

The Domain For Sale plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class_name’ parameter in all versions up to, and including, 3.0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Domain For Sale

CVE-2025-5239

MEDIUM CVSS 6.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5760 - Simple History Plugin

The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective Mode due to improper sanitization within the append_debug_info_to_context() function in versions prior to 5.8.1. When Detective Mode is enabled, the plugin’s logger captures the entire contents of $_POST (and sometimes raw request bodies or $_GET) without redacting any password‐related keys. As a result, whenever a user submits a login form, whether via native wp_login or a third‐party login widget, their actual password is written in clear text into the logs. An authenticated attacker or any user…

PLUGIN Simple History

CVE-2025-5760

MEDIUM CVSS 4.9 2025-06-06
Threat Entry Updated 2025-07-15

CVE-2025-5703 - Stageshow Plugin

The StageShow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘anchor’ parameter in all versions up to, and including, 10.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Stageshow

CVE-2025-5703

MEDIUM CVSS 6.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5686 - Paged Gallery Plugin

The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Paged Gallery

CVE-2025-5686

MEDIUM CVSS 6.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5699 - Devformatter Plugin

The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2015.0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Devformatter

CVE-2025-5699

MEDIUM CVSS 5.5 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5563 - Wp Addpub Plugin

The WP-Addpub plugin for WordPress is vulnerable to SQL Injection via the 'wp-addpub' shortcode in all versions up to, and including, 1.2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Addpub

CVE-2025-5563

MEDIUM CVSS 6.5 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5586 - Cpt Ajax Load More Plugin

The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cpt Ajax Load More

CVE-2025-5586

MEDIUM CVSS 6.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5565 - Hide It Plugin

The Hide It plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hideit' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Hide It

CVE-2025-5565

MEDIUM CVSS 6.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5541 - Runners Log Plugin

The Runners Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'runnerslog' shortcode in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Runners Log

CVE-2025-5541

MEDIUM CVSS 6.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5538 - Bns Featured Category Plugin

The BNS Featured Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bnsfc' shortcode in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bns Featured Category

CVE-2025-5538

MEDIUM CVSS 6.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5486 - Wp Email Debug Plugin

The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 to 1.1.0. This makes it possible for unauthenticated attackers to enable debugging and send all emails to an attacker controlled address and then trigger a password reset for an administrator to gain access to an administrator account.

PLUGIN Wp Email Debug

CVE-2025-5486

CRITICAL CVSS 9.8 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5536 - Wp Freemind Plugin

The Freemind Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'freemind' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Freemind

CVE-2025-5536

MEDIUM CVSS 6.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5534 - Esv Bible Shortcode For Wordpress Plugin

The ESV Bible Shortcode for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'esv' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Esv Bible Shortcode For Wordpress

CVE-2025-5534

MEDIUM CVSS 6.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5533 - Knowledge Base Plugin

The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kbalert' shortcode in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Knowledge Base

CVE-2025-5533

MEDIUM CVSS 6.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5019 - Hive Support Plugin

The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the hs_update_ai_chat_settings() function. This makes it possible for unauthenticated attackers to reconfigure the plugin’s AI/chat settings (including API keys) and to potentially redirect notifications or leak data to attacker-controlled endpoints via a forged request granted they can trick a site administrator into performing an action such as…

PLUGIN Hive Support

CVE-2025-5019

MEDIUM CVSS 5.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5018 - Hive Support Plugin

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read and overwrite the site’s OpenAI API key and inspection data or modify AI-chat prompts and behavior. This vulnerability is potentially a duplicate of CVE-2025-32208 or/and CVE-2025-32242.

PLUGIN Hive Support

CVE-2025-5018

HIGH CVSS 7.1 2025-06-06
Threat Entry Updated 2025-07-10

CVE-2025-4966 - Wp Online Users Stats Plugin

The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation within the hk_dataset_results() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Online Users Stats

CVE-2025-4966

MEDIUM CVSS 6.1 2025-06-06
Scroll to top