Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,846
Critical959
High3,226
Medium11,383
Reset
Showing 5761-5780 of 15846 records
Threat Entry Updated 2025-05-21

CVE-2024-12561 - Affiliate Sales In Google Analytics And Other Tools Plugin

The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.4.9. This is due to insufficient validation on the redirect url supplied via the 'afflink' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

PLUGIN Affiliate Sales In Google Analytics And Other Tools

CVE-2024-12561

MEDIUM CVSS 6.1 2025-05-21
Threat Entry Updated 2025-05-21

CVE-2024-5878 - Nextgen Gallery Plugin

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox JavaScript library (version 2.1.5) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Nextgen Gallery

CVE-2024-5878

MEDIUM CVSS 6.4 2025-05-20
Threat Entry Updated 2025-06-12

CVE-2025-2929 - Order Delivery Date Plugin

The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Order Delivery Date

CVE-2025-2929

HIGH CVSS 7.1 2025-05-20
Threat Entry Updated 2026-01-22

CVE-2025-39352 - Grand Restaurant Plugin

Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-39352

HIGH CVSS 8.2 2025-05-19
Threat Entry Updated 2025-05-29

CVE-2025-39348 - Grand Restaurant Plugin

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant WordPress allows Object Injection.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-39348

CRITICAL CVSS 9.8 2025-05-19
Threat Entry Updated 2025-06-09

CVE-2025-32926 - Grand Restaurant Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaurant WordPress allows Path Traversal.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-32926

CRITICAL CVSS 9.8 2025-05-19
Threat Entry Updated 2025-05-21

CVE-2025-39411 - Plugins Whatsapp Click To Chat

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Indie_Plugins WhatsApp Click to Chat Plugin for WordPress.This issue affects WhatsApp Click to Chat Plugin for WordPress: from n/a through 2.2.12.

PLUGIN Plugins Whatsapp Click To Chat

CVE-2025-39411

HIGH CVSS 7.5 2025-05-19
Threat Entry Updated 2026-01-22

CVE-2025-39353 - Grand Restaurant Plugin

Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-39353

MEDIUM CVSS 5.3 2025-05-19
Threat Entry Updated 2026-01-22

CVE-2025-39351 - Grand Restaurant Plugin

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant WordPress allows Cross Site Request Forgery.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-39351

MEDIUM CVSS 4.3 2025-05-19
Threat Entry Updated 2026-01-09

CVE-2025-2561 - Ninja Forms Plugin

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Ninja Forms

CVE-2025-2561

MEDIUM CVSS 4.8 2025-05-19
Threat Entry Updated 2026-01-09

CVE-2025-2560 - Ninja Forms Plugin

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Ninja Forms

CVE-2025-2560

MEDIUM CVSS 4.8 2025-05-19
Threat Entry Updated 2026-01-09

CVE-2025-2524 - Ninja Forms Plugin

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Ninja Forms

CVE-2025-2524

MEDIUM CVSS 4.8 2025-05-19
Threat Entry Updated 2026-01-09

CVE-2025-1627 - Qi Blocks Plugin

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Qi Blocks

CVE-2025-1627

MEDIUM CVSS 5.4 2025-05-19
Threat Entry Updated 2026-01-09

CVE-2025-1626 - Qi Blocks Plugin

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Qi Blocks

CVE-2025-1626

MEDIUM CVSS 5.4 2025-05-19
Threat Entry Updated 2026-01-09

CVE-2025-1625 - Qi Blocks Plugin

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Qi Blocks

CVE-2025-1625

MEDIUM CVSS 5.4 2025-05-19
Threat Entry Updated 2025-06-04

CVE-2025-2892 - All In One Seo Plugin

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post Meta Description and Canonical URL parameters in all versions up to, and including, 4.8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN All In One Seo

CVE-2025-2892

MEDIUM CVSS 6.4 2025-05-19
Threat Entry Updated 2025-05-19

CVE-2025-3715 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2025-3715

MEDIUM CVSS 6.4 2025-05-18
Threat Entry Updated 2025-05-28

CVE-2025-4101 - Multivendorx Plugin

The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'delete_fpm_product' function in all versions up to, and including, 4.2.22. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary posts, pages, attachments, and products. The vulnerability was partially patched in version 4.2.22.

PLUGIN Multivendorx

CVE-2025-4101

MEDIUM CVSS 4.3 2025-05-17
Threat Entry Updated 2025-06-04

CVE-2025-4669 - Wp Booking Calendar Plugin

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Booking Calendar

CVE-2025-4669

MEDIUM CVSS 6.4 2025-05-17
Scroll to top