Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14,261
Critical855
High2,811
Medium10,399
Reset
Showing 1761-1780 of 14261 records
Threat Entry Updated 2026-01-13

CVE-2025-13934 - Elearning And Online Course Solution Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollment in all versions up to, and including, 3.9.3. This is due to a missing capability check and purchasability validation in the `course_enrollment()` AJAX handler. This makes it possible for authenticated attackers, with subscriber level access and above, to enroll themselves in any course without going through the proper purchase flow.

PLUGIN Elearning And Online Course Solution

CVE-2025-13934

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13753 - Drop Table Builder Plugin

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect authorization check on the save_table() function in all versions up to, and including, 2.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new wptb-table posts.

PLUGIN Drop Table Builder

CVE-2025-13753

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13628 - Elearning And Online Course Solution Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability check on the 'bulk_action_handler' and 'coupon_permanent_delete' functions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with subscriber level access and above, to delete, activate, deactivate, or trash arbitrary coupons.

PLUGIN Elearning And Online Course Solution

CVE-2025-13628

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-01-15

CVE-2026-20969 - Samsung Mobile Devices Plugin

Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.

PLUGIN Samsung Mobile Devices

CVE-2026-20969

LOW CVSS 2.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-15057 - Slimstat Analytics Plugin

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) parameter in all versions up to, and including, 5.3.3. This is due to insufficient input sanitization and output escaping on the fingerprint value stored in the database. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the Real-time Access Log report.

PLUGIN Slimstat Analytics

CVE-2025-15057

HIGH CVSS 7.2 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-15055 - Slimstat Analytics Plugin

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' parameters in all versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the Recent Custom Events report.

PLUGIN Slimstat Analytics

CVE-2025-15055

HIGH CVSS 7.2 2026-01-09
Threat Entry Updated 2026-04-15

CVE-2026-0563 - WP Google Street View (with 360° virtual tour) & Google maps + Local SEO Plugin

The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpgsv_map' shortcode in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN WP Google Street View (with 360° virtual tour) & Google maps + Local SEO

CVE-2026-0563

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-15019 - Woocommerce Plugin

The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bialty_cs_alt' post meta in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the post editor.

PLUGIN Woocommerce

CVE-2025-15019

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14736 - Frontend Admin By Dynamiapps Plugin

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.25. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field.

PLUGIN Frontend Admin By Dynamiapps

CVE-2025-14736

CRITICAL CVSS 9.8 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14980 - Betterdocs Plugin

The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in plugin settings.

PLUGIN Betterdocs

CVE-2025-14980

MEDIUM CVSS 6.5 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14893 - Indieweb Plugin

The IndieWeb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Telephone' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Indieweb

CVE-2025-14893

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14782 - Custom Form Builder Plugin

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.49.1 via the 'listen_for_csv_export' function. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with access to the Forminator dashboard, to export sensitive form submission data including personally identifiable information.

PLUGIN Custom Form Builder

CVE-2025-14782

MEDIUM CVSS 5.3 2026-01-09
Scroll to top