Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 561-580 of 1249 records
Threat Entry Updated 2025-09-08

CVE-2025-8359 - Adforest Theme

The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, including administrators, without access to a password.

THEME Adforest

CVE-2025-8359

CRITICAL CVSS 9.8 2025-09-06
Threat Entry Updated 2025-08-29

CVE-2025-7955 - Rccp Free Plugin

The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes.

PLUGIN Rccp Free

CVE-2025-7955

CRITICAL CVSS 9.8 2025-08-28
Threat Entry Updated 2025-08-25

CVE-2025-5821 - Case Theme User Plugin

The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly logging a user in with the data that was previously verified through the facebook_ajax_login_callback(). This makes it possible for unauthenticated attackers to log in as administrative users, as long as they have an existing account on the site, and access to the administrative user's email.

PLUGIN Case Theme User

CVE-2025-5821

CRITICAL CVSS 9.8 2025-08-23
Threat Entry Updated 2025-08-25

CVE-2025-7642 - Simpler Checkout Plugin

The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due to the plugin not properly verifying a user's identity prior to logging them in as an admin through the simplerwc_woocommerce_order_created() function. This makes it possible for unauthenticated attackers to log in as other users based on their order ID, which can be an administrator if a site admin has placed a test order.

PLUGIN Simpler Checkout

CVE-2025-7642

CRITICAL CVSS 9.8 2025-08-23
Threat Entry Updated 2025-08-22

CVE-2025-8895 - Wp Webhooks Plugin

The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and including, 3.3.5. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's server to arbitrary locations. This can be used to copy the contents of wp-config.php into a text file which can then be accessed in a browser to reveal database credentials.

PLUGIN Wp Webhooks

CVE-2025-8895

CRITICAL CVSS 9.8 2025-08-21
Threat Entry Updated 2025-12-12

CVE-2025-54677 - Online Booking Scheduling Calendar Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita allows Using Malicious Files. This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.5.3.

PLUGIN Online Booking Scheduling Calendar

CVE-2025-54677

CRITICAL CVSS 9.1 2025-08-20
Threat Entry Updated 2025-08-19

CVE-2025-8723 - Cf Image Resizing Plugin

The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to inject arbitrary PHP into the codebase, achieving remote code execution.

PLUGIN Cf Image Resizing

CVE-2025-8723

CRITICAL CVSS 9.8 2025-08-19
Threat Entry Updated 2025-08-19

CVE-2025-6758 - Real Spaces Wordpress Properties Directory Theme

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to arbitrarily choose their role, including the Administrator role, during user registration.

THEME Real Spaces Wordpress Properties Directory Theme

CVE-2025-6758

CRITICAL CVSS 9.8 2025-08-19
Threat Entry Updated 2025-08-18

CVE-2025-8898 - Ecab Taxi Booking Manager Plugin

The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.0. This is due to the plugin not properly validating a user's capabilities prior to updating a plugin setting or their identity prior to updating their details like email address. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

PLUGIN Ecab Taxi Booking Manager

CVE-2025-8898

CRITICAL CVSS 9.8 2025-08-16
Threat Entry Updated 2025-08-18

CVE-2025-7441 - Story Chief Plugin

The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs through the /wp-json/storychief/webhook REST-API endpoint that does not have sufficient filetype validation. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Story Chief

CVE-2025-7441

CRITICAL CVSS 9.8 2025-08-16
Threat Entry Updated 2025-08-15

CVE-2025-7778 - Icons Factory Plugin

The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete_files() function in all versions up to, and including, 1.6.12. This makes it possible for unauthenticated attackers to to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Icons Factory

CVE-2025-7778

CRITICAL CVSS 9.8 2025-08-15
Threat Entry Updated 2025-08-15

CVE-2025-6679 - Bit Form Plugin

The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.20.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. For this to be exploitable, the PRO version needs to be installed and activated as well. Additionally a form with an advanced file upload element needs to be published.

PLUGIN Bit Form

CVE-2025-6679

CRITICAL CVSS 9.8 2025-08-15
Threat Entry Updated 2025-08-14

CVE-2025-8047 - WordPress component

The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security services. Users that pay are added to allowedDomains to suppress the popup.

UNKNOWN WordPress component

CVE-2025-8047

CRITICAL CVSS 9.8 2025-08-14
Threat Entry Updated 2025-08-13

CVE-2025-6715 - Before 5 Plugin

The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

PLUGIN Before 5

CVE-2025-6715

CRITICAL CVSS 9.8 2025-08-13
Threat Entry Updated 2025-08-13

CVE-2025-7384 - Contact Form Entries Plugin

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file is deleted.

PLUGIN Contact Form Entries

CVE-2025-7384

CRITICAL CVSS 9.8 2025-08-13
Threat Entry Updated 2025-08-12

CVE-2025-8059 - B Blocks Plugin

The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_registration() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to create a new account and assign it the administrator role.

PLUGIN B Blocks

CVE-2025-8059

CRITICAL CVSS 9.8 2025-08-12
Threat Entry Updated 2025-08-06

CVE-2025-6994 - WordPress component

The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'listing_user_role' field. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.

UNKNOWN WordPress component

CVE-2025-6994

CRITICAL CVSS 9.8 2025-08-06
Threat Entry Updated 2025-08-04

CVE-2025-7710 - WordPress component

The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Facebook. This makes it possible for unauthenticated attackers to log in as other users, including administrators.

UNKNOWN WordPress component

CVE-2025-7710

CRITICAL CVSS 9.8 2025-08-02
Threat Entry Updated 2025-10-23

CVE-2025-5947 - Service Finder Bookings Plugin

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to logging them in through the service_finder_switch_back() function. This makes it possible for unauthenticated attackers to login as any user including admins.

PLUGIN Service Finder Bookings

CVE-2025-5947

CRITICAL CVSS 9.8 2025-08-01
Threat Entry Updated 2025-08-04

CVE-2025-5954 - Service Finder Sms System Plugin

The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not restricting user role selection at the time of registration through the aonesms_fn_savedata_after_signup() function. This makes it possible for unauthenticated attackers to register as an administrator user.

PLUGIN Service Finder Sms System

CVE-2025-5954

CRITICAL CVSS 9.8 2025-08-01
Scroll to top