Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 521-540 of 1249 records
Threat Entry Updated 2025-10-30

CVE-2025-4665 - Contact Form Cfdb7 Plugin

WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injection vulnerability that cascades into insecure deserialization (PHP Object Injection). The weakness arises due to insufficient validation of user input in plugin endpoints, allowing crafted input to influence backend queries in unexpected ways. Using specially crafted payloads, this can escalate into unsafe deserialization, enabling arbitrary object injection in PHP. Although the issue is remotely exploitable without authentication, it does require a crafted interaction with the affected endpoint in order to trigger successfully.

PLUGIN Contact Form Cfdb7

CVE-2025-4665

CRITICAL CVSS 9.6 2025-10-29
Threat Entry Updated 2025-10-27

CVE-2025-6440 - Woocommerce Designer Pro Plugin

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Woocommerce Designer Pro

CVE-2025-6440

CRITICAL CVSS 9.8 2025-10-24
Threat Entry Updated 2025-10-21

CVE-2025-10916 - Before 1 Plugin

The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

PLUGIN Before 1

CVE-2025-10916

CRITICAL CVSS 9.1 2025-10-21
Threat Entry Updated 2025-10-21

CVE-2025-11391 - Woocommerce Product Addon Plugin

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image cropper functionality in all versions up to, and including, 33.0.15. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. While the vulnerable code is in the free version, this only affected users with the paid version of the software installed and activated.

PLUGIN Woocommerce Product Addon

CVE-2025-11391

CRITICAL CVSS 9.8 2025-10-18
Threat Entry Updated 2025-10-16

CVE-2025-10850 - Felan Framework Plugin

The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password in the 'fb_ajax_login_or_register' function and in the 'google_ajax_login_or_register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they registered with facebook or google social login and did not change their password.

PLUGIN Felan Framework

CVE-2025-10850

CRITICAL CVSS 9.8 2025-10-16
Threat Entry Updated 2025-10-16

CVE-2025-10742 - Truelysell Core Plugin

The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.8.6. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited unauthenticated if the attacker knows which page contains the 'truelysell_edit_staff' shortcode.

PLUGIN Truelysell Core

CVE-2025-10742

CRITICAL CVSS 9.8 2025-10-16
Threat Entry Updated 2025-10-16

CVE-2025-9967 - Orion Sms Otp Verification Plugin

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's password to a one-time password if the attacker knows the user's phone number

PLUGIN Orion Sms Otp Verification

CVE-2025-9967

CRITICAL CVSS 9.8 2025-10-15
Threat Entry Updated 2025-10-16

CVE-2025-10294 - Ownid Passwordless Login Plugin

The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to log in as other users, including administrators, on instances where the plugin has not been fully configured yet.

PLUGIN Ownid Passwordless Login

CVE-2025-10294

CRITICAL CVSS 9.8 2025-10-15
Threat Entry Updated 2025-10-16

CVE-2025-10041 - Flex Qr Code Generator Plugin

The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in thesave_qr_code_to_db() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Flex Qr Code Generator

CVE-2025-10041

CRITICAL CVSS 9.8 2025-10-15
Threat Entry Updated 2025-10-14

CVE-2025-6439 - Woocommerce Designer Pro Plugin

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for unauthenticated attackers to delete all files in an arbitrary directory on the server, which can lead to remote code execution, data loss, or site unavailability.

PLUGIN Woocommerce Designer Pro

CVE-2025-6439

CRITICAL CVSS 9.8 2025-10-11
Threat Entry Updated 2025-10-14

CVE-2025-6553 - Ovatheme Events Manager Plugin

The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_checkout() function in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Ovatheme Events Manager

CVE-2025-6553

CRITICAL CVSS 9.8 2025-10-11
Threat Entry Updated 2025-10-14

CVE-2025-11533 - Wp Freeio Plugin

The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. This is due to the process_register() function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

PLUGIN Wp Freeio

CVE-2025-11533

CRITICAL CVSS 9.8 2025-10-11
Threat Entry Updated 2025-10-09

CVE-2025-11522 - Go Directory Wordpress Theme

The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elated_check_facebook_user() function This makes it possible for unauthenticated attackers to gain access to other user's accounts, including administrators, when Facebook login is enabled.

THEME Go Directory Wordpress Theme

CVE-2025-11522

CRITICAL CVSS 9.8 2025-10-09
Threat Entry Updated 2025-10-09

CVE-2025-7634 - Wp Travel Engine Plugin

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

PLUGIN Wp Travel Engine

CVE-2025-7634

CRITICAL CVSS 9.8 2025-10-09
Threat Entry Updated 2025-10-09

CVE-2025-7526 - Wp Travel Engine Plugin

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versions up to, and including, 6.6.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Wp Travel Engine

CVE-2025-7526

CRITICAL CVSS 9.8 2025-10-09
Threat Entry Updated 2025-10-09

CVE-2025-10586 - Community Events Plugin

The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Community Events

CVE-2025-10586

CRITICAL CVSS 9.8 2025-10-09
Threat Entry Updated 2025-10-08

CVE-2025-10587 - Community Events Plugin

The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Community Events

CVE-2025-10587

CRITICAL CVSS 9.8 2025-10-08
Threat Entry Updated 2025-10-06

CVE-2025-9485 - Miniorange Login With Eve Online Google Facebook Plugin

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token processing without verification or validation in the `get_resource_owner_from_id_token` function. This makes it possible for unauthenticated attackers to bypass authentication and gain access to any existing user account - including administrators in certain configurations - or to create arbitrary subscriber-level accounts.

PLUGIN Miniorange Login With Eve Online Google Facebook

CVE-2025-9485

CRITICAL CVSS 9.8 2025-10-04
Threat Entry Updated 2025-10-06

CVE-2025-9286 - Appy Pie Connect For Woocommerce Plugin

The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to reset the password of arbitrary users, including administrators, thereby gaining administrative access.

PLUGIN Appy Pie Connect For Woocommerce

CVE-2025-9286

CRITICAL CVSS 9.8 2025-10-03
Threat Entry Updated 2025-10-06

CVE-2025-9209 - Restropress Plugin

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due to the plugin exposing user private tokens and API data via the /wp-json/wp/v2/users REST API endpoint. This makes it possible for unauthenticated attackers to forge JWT tokens for other users, including administrators, and authenticate as them.

PLUGIN Restropress

CVE-2025-9209

CRITICAL CVSS 9.8 2025-10-03
Scroll to top