Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 621-640 of 1249 records
Threat Entry Updated 2025-06-06

CVE-2025-5486 - Wp Email Debug Plugin

The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 to 1.1.0. This makes it possible for unauthenticated attackers to enable debugging and send all emails to an attacker controlled address and then trigger a password reset for an administrator to gain access to an administrator account.

PLUGIN Wp Email Debug

CVE-2025-5486

CRITICAL CVSS 9.8 2025-06-06
Threat Entry Updated 2025-06-05

CVE-2025-5701 - Hypercomments Plugin

The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hc_request_handler function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

PLUGIN Hypercomments

CVE-2025-5701

CRITICAL CVSS 9.8 2025-06-05
Threat Entry Updated 2025-06-04

CVE-2025-4578 - File Provider Plugin

The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN File Provider

CVE-2025-4578

CRITICAL CVSS 9.8 2025-06-04
Threat Entry Updated 2025-06-04

CVE-2025-4797 - Golo City Travel Guide Wordpress Theme

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is due to the plugin not properly validating a user's identity prior to setting an authorization cookie. This makes it possible for unauthenticated attackers to log in as any user, including administrators, provided they know the user's email address.

THEME Golo City Travel Guide Wordpress Theme

CVE-2025-4797

CRITICAL CVSS 9.8 2025-06-03
Threat Entry Updated 2025-06-02

CVE-2025-4631 - Profitori Plugin

The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versions 2.0.6.0 to 2.1.1.3. This makes it possible to trigger the save_object_as_user() function for objects whose '_datatype' is set to 'users',. This allows unauthenticated attackers to write arbitrary strings straight into the user’s wp_capabilities meta field, potentially elevating the privileges of an existing user account or a newly created one to that of an administrator.

PLUGIN Profitori

CVE-2025-4631

CRITICAL CVSS 9.8 2025-05-31
Threat Entry Updated 2025-06-02

CVE-2025-4607 - Psw Login And Registration Plugin

The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() function. This is due to the use of a weak, low-entropy OTP mechanism in the forget() function. This makes it possible for unauthenticated attackers to initiate a password reset for any user, including administrators, and elevate their privileges for full site takeover.

PLUGIN Psw Login And Registration

CVE-2025-4607

CRITICAL CVSS 9.8 2025-05-31
Threat Entry Updated 2025-07-11

CVE-2025-5058 - Emagicone Store Manager For Woocommerce Plugin

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This is only exploitable by unauthenticated attackers in default configurations where the the default password is left as 1:1, or where the attacker gains access to the credentials.

PLUGIN Emagicone Store Manager For Woocommerce

CVE-2025-5058

CRITICAL CVSS 9.8 2025-05-24
Threat Entry Updated 2025-07-11

CVE-2025-4603 - Emagicone Store Manager For Woocommerce Plugin

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is only exploitable by unauthenticated attackers in default configurations where the the default password is left as 1:1, or where the attacker gains access to…

PLUGIN Emagicone Store Manager For Woocommerce

CVE-2025-4603

CRITICAL CVSS 9.1 2025-05-24
Threat Entry Updated 2025-12-05

CVE-2025-47658 - Wsdesk Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System allows Upload a Web Shell to a Web Server. This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through 3.2.7.

PLUGIN Wsdesk

CVE-2025-47658

CRITICAL CVSS 9.9 2025-05-23
Threat Entry Updated 2026-01-28

CVE-2025-39485 - Grand Tour Plugin

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour | Travel Agency WordPress allows Object Injection. This issue affects Grand Tour | Travel Agency WordPress: from n/a through 5.5.1.

PLUGIN Grand Tour

CVE-2025-39485

CRITICAL CVSS 9.8 2025-05-23
Threat Entry Updated 2025-05-23

CVE-2025-31914 - Pixel WordPress Form BuilderPlugin & Autoresponder

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder allows Blind SQL Injection. This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through 1.0.2.

PLUGIN Pixel WordPress Form BuilderPlugin & Autoresponder

CVE-2025-31914

CRITICAL CVSS 9.3 2025-05-23
Threat Entry Updated 2025-05-21

CVE-2025-4524 - Responsive And Modern Wordpress Theme For Manga Sites

The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

THEME Responsive And Modern Wordpress Theme For Manga Sites

CVE-2025-4524

CRITICAL CVSS 9.8 2025-05-21
Threat Entry Updated 2025-05-21

CVE-2025-4322 - Motors Theme

The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user passwords, including those of administrators, and leverage that to gain access to their account.

THEME Motors

CVE-2025-4322

CRITICAL CVSS 9.8 2025-05-20
Threat Entry Updated 2025-05-29

CVE-2025-39348 - Grand Restaurant Plugin

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant WordPress allows Object Injection.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-39348

CRITICAL CVSS 9.8 2025-05-19
Threat Entry Updated 2025-06-09

CVE-2025-32926 - Grand Restaurant Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaurant WordPress allows Path Traversal.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-32926

CRITICAL CVSS 9.8 2025-05-19
Threat Entry Updated 2025-05-21

CVE-2025-47582 - WordPress Core

Deserialization of Untrusted Data vulnerability in QuantumCloud WPBot Pro Wordpress Chatbot allows Object Injection.This issue affects WPBot Pro Wordpress Chatbot: from n/a through 12.7.0.

CORE WordPress Core

CVE-2025-47582

CRITICAL CVSS 9.8 2025-05-19
Threat Entry Updated 2025-05-19

CVE-2025-4391 - Echo Rss Feed Post Generator Plugin

The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the echo_generate_featured_image() function in all versions up to, and including, 5.4.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Echo Rss Feed Post Generator

CVE-2025-4391

CRITICAL CVSS 9.8 2025-05-17
Scroll to top