Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 581-600 of 1249 records
Threat Entry Updated 2025-07-29

CVE-2025-6895 - Melapress Login Security Plugin

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks and log in as that user.

PLUGIN Melapress Login Security

CVE-2025-6895

CRITICAL CVSS 9.8 2025-07-26
Threat Entry Updated 2025-07-25

CVE-2025-6441 - Webinar Ignition Plugin

The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login token generation due to a missing capability check on the `webinarignition_sign_in_support_staff` and `webinarignition_register_support` functions in all versions up to, and including, 4.03.31. This makes it possible for unauthenticated attackers to generate login tokens for arbitrary WordPress users under certain circumstances, issuing authorization cookies which can lead to authentication bypass.

PLUGIN Webinar Ignition

CVE-2025-6441

CRITICAL CVSS 9.8 2025-07-24
Threat Entry Updated 2025-07-25

CVE-2025-6380 - Onlyoffice Docs Plugin

The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in versions 1.1.0 to 2.2.0. The plugin’s permission callback only verifies that the supplied, encrypted attachment ID maps to an existing attachment post, but does not verify the requester’s identity or capabilities. This makes it possible for unauthenticated attackers to log in as an arbitrary user.

PLUGIN Onlyoffice Docs

CVE-2025-6380

CRITICAL CVSS 9.8 2025-07-24
Threat Entry Updated 2025-07-25

CVE-2025-7852 - Wpbookit Plugin

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_customer' route in all versions up to, and including, 1.0.6. The plugin’s image‐upload handler calls move_uploaded_file() on client‐supplied files without restricting allowed extensions or MIME types, nor sanitizing the filename. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wpbookit

CVE-2025-7852

CRITICAL CVSS 9.8 2025-07-24
Threat Entry Updated 2025-07-25

CVE-2025-7437 - Ebook Store Plugin

The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to, and including, 5.8012. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Ebook Store

CVE-2025-7437

CRITICAL CVSS 9.8 2025-07-24
Threat Entry Updated 2025-07-22

CVE-2025-6187 - Bsecure Plugin

The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_info REST endpoint in versions 1.3.7 through 1.7.9. The plugin registers the /webhook/v2/order_info/ route with a permission_callback that always returns true, effectively bypassing all authentication. This makes it possible for unauthenticated attackers who know any user’s email to obtain a valid login cookie and fully impersonate that account.

PLUGIN Bsecure

CVE-2025-6187

CRITICAL CVSS 9.8 2025-07-22
Threat Entry Updated 2025-07-22

CVE-2025-7697 - Integration For Contact Form 7 And Google Sheets Plugin

The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php…

PLUGIN Integration For Contact Form 7 And Google Sheets

CVE-2025-7697

CRITICAL CVSS 9.8 2025-07-19
Threat Entry Updated 2025-07-22

CVE-2025-7696 - Integration For Contact Form 7 And Pipedrive Plugin

The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.3 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file…

PLUGIN Integration For Contact Form 7 And Pipedrive

CVE-2025-7696

CRITICAL CVSS 9.8 2025-07-19
Threat Entry Updated 2025-07-22

CVE-2025-7444 - Loginpress Pro Plugin

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

PLUGIN Loginpress Pro

CVE-2025-7444

CRITICAL CVSS 9.8 2025-07-18
Threat Entry Updated 2025-07-22

CVE-2025-7643 - Attachment Manager Plugin

The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handle_actions() function in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Attachment Manager

CVE-2025-7643

CRITICAL CVSS 9.1 2025-07-18
Threat Entry Updated 2025-07-22

CVE-2025-6222 - Manage User Wallet Theme

The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ced_rnx_order_exchange_attach_files' function in all versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

THEME Manage User Wallet

CVE-2025-6222

CRITICAL CVSS 9.8 2025-07-18
Threat Entry Updated 2025-07-17

CVE-2025-7712 - Madara Core Plugin

The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_delete_zip() function in all versions up to, and including, 2.2.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Madara Core

CVE-2025-7712

CRITICAL CVSS 9.1 2025-07-17
Threat Entry Updated 2025-07-17

CVE-2025-5396 - Bears Backup Plugin

The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input passed directly to call_user_func(). This makes it possible for unauthenticated attackers to execute code on the server which can be leverage to inject backdoors or create new administrative user accounts to name a few things. On WordPress sites running the Alone theme versions 7.8.4 and older, this can be chained with CVE-2025-5394 to…

PLUGIN Bears Backup

CVE-2025-5396

CRITICAL CVSS 9.8 2025-07-17
Threat Entry Updated 2025-07-16

CVE-2025-24759 - WP-BusinessDirectory Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory allows Blind SQL Injection. This issue affects WP-BusinessDirectory: from n/a through 3.1.3.

PLUGIN WP-BusinessDirectory

CVE-2025-24759

CRITICAL CVSS 9.3 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-7360 - Download Contact Form 7 Widget For Elementor Page Builder Gutenberg Blocks Plugin

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation in the handle_files_upload() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php).

PLUGIN Download Contact Form 7 Widget For Elementor Page Builder Gutenberg Blocks

CVE-2025-7360

CRITICAL CVSS 9.1 2025-07-15
Threat Entry Updated 2025-07-16

CVE-2025-7341 - Download Contact Form 7 Widget For Elementor Page Builder Gutenberg Blocks Plugin

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Download Contact Form 7 Widget For Elementor Page Builder Gutenberg Blocks

CVE-2025-7341

CRITICAL CVSS 9.1 2025-07-15
Threat Entry Updated 2025-07-16

CVE-2025-7340 - Download Contact Form 7 Widget For Elementor Page Builder Gutenberg Blocks Plugin

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the temp_file_upload function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Download Contact Form 7 Widget For Elementor Page Builder Gutenberg Blocks

CVE-2025-7340

CRITICAL CVSS 9.8 2025-07-15
Threat Entry Updated 2025-07-15

CVE-2025-5394 - Charity Multipurpose Non Profit Wordpress Theme

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution.

THEME Charity Multipurpose Non Profit Wordpress Theme

CVE-2025-5394

CRITICAL CVSS 9.8 2025-07-15
Threat Entry Updated 2025-07-15

CVE-2025-5393 - Charity Multipurpose Non Profit Wordpress Theme

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the alone_import_pack_restore_data() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

THEME Charity Multipurpose Non Profit Wordpress Theme

CVE-2025-5393

CRITICAL CVSS 9.1 2025-07-15
Threat Entry Updated 2025-07-16

CVE-2025-6058 - Wpbookit Plugin

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wpbookit

CVE-2025-6058

CRITICAL CVSS 9.8 2025-07-12
Scroll to top