Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,846
Critical959
High3,226
Medium11,383
Reset
Showing 6141-6160 of 15846 records
Threat Entry Updated 2025-04-29

CVE-2025-1565 - Mayosis Core Plugin

The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 via the library/wave-audio/peaks/remote_dl.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Mayosis Core

CVE-2025-1565

HIGH CVSS 7.5 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-1279 - Bm Content Builder Plugin

The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ux_cb_tools_import_item_ajax AJAX action in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

PLUGIN Bm Content Builder

CVE-2025-1279

HIGH CVSS 8.8 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3870 - 1 Decembrie 1918 Plugin

The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.dec.2012. This is due to missing or incorrect nonce validation on the 1-decembrie-1918/1-decembrie-1918.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN 1 Decembrie 1918

CVE-2025-3870

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3868 - Admin Bookmarks Plugin

The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Admin Bookmarks

CVE-2025-3868

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3867 - Ajax Comment Form Cst Plugin

The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation via the 'acform_cst_settings' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ajax Comment Form Cst

CVE-2025-3867

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3866 - Add Google Plus One Social Share Button Plugin

The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the google-plus-one-share-button page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Add Google Plus One Social Share Button

CVE-2025-3866

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3743 - Upsell Order Bump Offer For Woocommerce Plugin

The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the 'add_offer_in_cart' function. This makes it possible for unauthenticated attackers to arbitrarily update the product associated with any order bump, and arbitrarily update the discount applied to any order bump item, when adding it to the cart.

PLUGIN Upsell Order Bump Offer For Woocommerce

CVE-2025-3743

MEDIUM CVSS 5.3 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3923 - Prevent Direct Access Plugin

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'generate_unique_string' due to insufficient randomness of the generated file name. This makes it possible for unauthenticated attackers to extract sensitive data including files protected by the plugin if the attacker can determine the file name.

PLUGIN Prevent Direct Access

CVE-2025-3923

MEDIUM CVSS 5.3 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3861 - Prevent Direct Access Plugin

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability check on the 'pda_lite_custom_permission_check' function in versions 2.8.6 to 2.8.8.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to access and change the protection status of media.

PLUGIN Prevent Direct Access

CVE-2025-3861

MEDIUM CVSS 5.4 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-2580 - Bit Form Plugin

The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Bit Form

CVE-2025-2580

MEDIUM CVSS 4.9 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-0671 - Icegram Express Plugin

The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Icegram Express

CVE-2025-0671

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-11-26

CVE-2025-3775 - Shoplentor Plugin

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application, and can be used to query and modify information from internal services.

PLUGIN Shoplentor

CVE-2025-3775

MEDIUM CVSS 6.5 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3752 - Accessible Html5 Media Player Plugin

The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘preload’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Accessible Html5 Media Player

CVE-2025-3752

MEDIUM CVSS 6.4 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3749 - Wt Display Breeze Plugin

The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wt Display Breeze

CVE-2025-3749

MEDIUM CVSS 6.4 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-1294 - Eform Wordpress Form Builder Plugin

The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.18.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Eform Wordpress Form Builder

CVE-2025-1294

HIGH CVSS 7.2 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-3832 - Fusedesk Plugin

The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Fusedesk

CVE-2025-3832

MEDIUM CVSS 6.4 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-3793 - Buddy Press Force Password Change Plugin

The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with subscriber-level access and above and under certain prerequisites, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their accounts.

PLUGIN Buddy Press Force Password Change

CVE-2025-3793

MEDIUM CVSS 4.2 2025-04-24
Threat Entry Updated 2025-08-12

CVE-2025-3604 - Flynax Bridge Plugin

The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

PLUGIN Flynax Bridge

CVE-2025-3604

CRITICAL CVSS 9.8 2025-04-24
Threat Entry Updated 2025-08-12

CVE-2025-3603 - Flynax Bridge Plugin

The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Flynax Bridge

CVE-2025-3603

CRITICAL CVSS 9.8 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-3607 - Frontend Login And Registration Blocks Plugin

The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.7. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Frontend Login And Registration Blocks

CVE-2025-3607

HIGH CVSS 8.8 2025-04-24
Scroll to top