Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14,262
Critical855
High2,812
Medium10,399
Reset
Showing 1961-1980 of 14262 records
Threat Entry Updated 2026-01-08

CVE-2025-14626 - Qr Code Tag For Wc From Goaskle Com Plugin

The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 1.9.42 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Qr Code Tag For Wc From Goaskle Com

CVE-2025-14626

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14468 - Accelerated Mobile Pages Plugin

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to inverted nonce verification logic in the amp_theme_ajaxcomments AJAX handler, which rejects requests with VALID nonces and accepts requests with MISSING or INVALID nonces. This makes it possible for unauthenticated attackers to submit comments on behalf of logged-in users via a forged request granted they can trick a user into performing an action such as clicking on a link, and the plugin's template…

PLUGIN Accelerated Mobile Pages

CVE-2025-14468

MEDIUM CVSS 4.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14465 - Sticky Action Buttons Plugin

The Sticky Action Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the sabs_options_page_form_submit() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Sticky Action Buttons

CVE-2025-14465

MEDIUM CVSS 4.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14453 - My Album Gallery Plugin

The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style_css' shortcode attribute in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN My Album Gallery

CVE-2025-14453

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14147 - Easy Github Gist Shortcodes Plugin

The Easy GitHub Gist Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the gist shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Github Gist Shortcodes

CVE-2025-14147

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14145 - Niche Hero Plugin

The Niche Hero | Beautifully-designed blocks in seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spacing' parameter of the nh_row shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Niche Hero

CVE-2025-14145

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14460 - Woo Payment Gateway For Piraeus Bank Plugin

The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modification in all versions up to, and including, 3.1.4. This is due to missing authorization checks on the payment callback endpoint handler when processing the 'fail' callback from the payment gateway. This makes it possible for unauthenticated attackers to change any order's status to 'failed' via the publicly accessible WooCommerce API endpoint by providing only the order ID (MerchantReference parameter), which can be easily enumerated as order IDs are sequential integers. This can cause significant…

PLUGIN Woo Payment Gateway For Piraeus Bank

CVE-2025-14460

MEDIUM CVSS 5.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14370 - Quote Comments Plugin

The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.0. This is due to missing authorization checks in the quotecomments_add_admin function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin options via the 'action' parameter.

PLUGIN Quote Comments

CVE-2025-14370

MEDIUM CVSS 5.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14352 - Awesome Hotel Booking Plugin

The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.php shortcode handler in all versions up to, and including, 1.0. This is due to the plugin relying solely on nonce verification without capability checks. This makes it possible for unauthenticated attackers to modify arbitrary booking records by obtaining a nonce from the public booking form.

PLUGIN Awesome Hotel Booking

CVE-2025-14352

MEDIUM CVSS 5.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14144 - Mstoic Shortcodes Plugin

The Mstoic Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'start' parameter of the ms_youtube_embeds shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mstoic Shortcodes

CVE-2025-14144

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14122 - Ad Sliding Faq Plugin

The AD Sliding FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliding_faq' shortcode in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ad Sliding Faq

CVE-2025-14122

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14121 - Edd Download Info Plugin

The EDD Download Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'edd_download_info_link' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Edd Download Info

CVE-2025-14121

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14131 - Wp Widget Changer Plugin

The WP Widget Changer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Widget Changer

CVE-2025-14131

MEDIUM CVSS 6.1 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14130 - Post Like Dislike Plugin

The Post Like Dislike plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Post Like Dislike

CVE-2025-14130

MEDIUM CVSS 6.1 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14128 - Stumble For Wordpress Plugin

The Stumble! for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Stumble For Wordpress

CVE-2025-14128

MEDIUM CVSS 6.1 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14127 - Testimonial Master Plugin

The Testimonial Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Testimonial Master

CVE-2025-14127

MEDIUM CVSS 6.1 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14114 - 1180px Shortcodes Plugin

The 1180px Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN 1180px Shortcodes

CVE-2025-14114

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14113 - Viitor Shortcodes Plugin

The Viitor Button Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' shortcode attribute in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Viitor Shortcodes

CVE-2025-14113

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14112 - Snillrik Restaurant Menu Plugin

The Snillrik Restaurant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'menu_style' shortcode attribute in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Snillrik Restaurant Menu

CVE-2025-14112

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-14110 - Wp Js List Pages Shortcodes Plugin

The WP Js List Pages Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to, and including, 1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Js List Pages Shortcodes

CVE-2025-14110

MEDIUM CVSS 6.4 2026-01-07
Scroll to top