Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 681-700 of 1249 records
Threat Entry Updated 2025-03-20

CVE-2025-2505 - Age Gate Plugin

The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Age Gate

CVE-2025-2505

CRITICAL CVSS 9.8 2025-03-20
Threat Entry Updated 2025-08-11

CVE-2025-2512 - File Away Plugin

The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the upload() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN File Away

CVE-2025-2512

CRITICAL CVSS 9.8 2025-03-19
Threat Entry Updated 2025-03-19

CVE-2024-13442 - Service Finder Bookings Plugin

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.0. This is due to the plugin not properly validating a user's identity prior to (1) performing a post-booking auto-login or (2) updating their profile details (e.g. password). This makes it possible for unauthenticated attackers to (1) login as an arbitrary user if their email address is known or (2) change an arbitrary user's password, including administrators, and leverage that to gain access to their account.

PLUGIN Service Finder Bookings

CVE-2024-13442

CRITICAL CVSS 9.8 2025-03-19
Threat Entry Updated 2025-03-19

CVE-2024-13790 - High Converting Ecommerce Wordpress Theme

The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.7.0 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

THEME High Converting Ecommerce Wordpress Theme

CVE-2024-13790

CRITICAL CVSS 9.8 2025-03-19
Threat Entry Updated 2025-03-19

CVE-2024-13410 - WordPress component

The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and including, 1.7.0, and in all versions up to, and including 3.9.0, respectively, via deserialization of untrusted input in the 'ajax_handler' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via…

UNKNOWN WordPress component

CVE-2024-13410

CRITICAL CVSS 9.8 2025-03-19
Threat Entry Updated 2025-03-19

CVE-2024-12922 - Altair Theme

The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check within functions.php in all versions up to, and including, 5.2.4. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

THEME Altair

CVE-2024-12922

CRITICAL CVSS 9.8 2025-03-19
Threat Entry Updated 2025-03-28

CVE-2025-1771 - Traveler Plugin

The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

PLUGIN Traveler

CVE-2025-1771

CRITICAL CVSS 9.8 2025-03-15
Threat Entry Updated 2025-03-25

CVE-2025-2232 - Realteo Plugin

The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authentication bypass in all versions up to, and including, 1.2.8. This is due to insufficient role restrictions in the 'do_register_user' function. This makes it possible for unauthenticated attackers to register an account with the Administrator role.

PLUGIN Realteo

CVE-2025-2232

CRITICAL CVSS 9.8 2025-03-14
Threat Entry Updated 2025-03-28

CVE-2024-13771 - Civi Plugin

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of user validation before changing a password. This makes it possible for unauthenticated attackers to change the password of arbitrary users, including administrators, if the attacker knows the username of the victim.

PLUGIN Civi

CVE-2024-13771

CRITICAL CVSS 9.8 2025-03-14
Threat Entry Updated 2025-03-21

CVE-2024-13824 - Ciyashop Plugin

The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.19.0 via deserialization of untrusted input in the 'add_ciyashop_wishlist' and 'ciyashop_get_compare' functions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed…

PLUGIN Ciyashop

CVE-2024-13824

CRITICAL CVSS 9.8 2025-03-14
Threat Entry Updated 2025-07-08

CVE-2024-11286 - Jobcareer Plugin

The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the cs_parse_request() function. This makes it possible for unauthenticated attackers to to log in to any user's account, including administrators.

PLUGIN Jobcareer

CVE-2024-11286

CRITICAL CVSS 9.8 2025-03-14
Threat Entry Updated 2025-07-08

CVE-2024-11285 - Jobcareer Plugin

The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email via the account_settings_callback() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

PLUGIN Jobcareer

CVE-2024-11285

CRITICAL CVSS 9.8 2025-03-14
Threat Entry Updated 2025-07-08

CVE-2024-11284 - Jobcareer Plugin

The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity prior to updating their password through the account_settings_save_callback() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Jobcareer

CVE-2024-11284

CRITICAL CVSS 9.8 2025-03-14
Threat Entry Updated 2025-04-02

CVE-2024-13446 - Workreap Plugin

The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly validating a user's identity prior to (1) performing a social auto-login or (2) updating their profile details (e.g. password). This makes it possible for unauthenticated attackers to (1) login as an arbitrary user if their email address is known or (2) change an arbitrary user's password, including administrators, and leverage that to gain access to their account. NOTE: This vulnerability was…

PLUGIN Workreap

CVE-2024-13446

CRITICAL CVSS 9.8 2025-03-12
Threat Entry Updated 2025-03-19

CVE-2025-1661 - Husky Products Filter Professional For Woocommerce Plugin

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Husky Products Filter Professional For Woocommerce

CVE-2025-1661

CRITICAL CVSS 9.8 2025-03-11
Threat Entry Updated 2025-03-13

CVE-2025-0177 - Javo Core Plugin

The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.

PLUGIN Javo Core

CVE-2025-0177

CRITICAL CVSS 9.8 2025-03-08
Threat Entry Updated 2025-03-13

CVE-2025-1315 - Injob Plugin

The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Injob

CVE-2025-1315

CRITICAL CVSS 9.8 2025-03-07
Threat Entry Updated 2025-03-13

CVE-2024-12876 - Golo Plugin

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Golo

CVE-2024-12876

CRITICAL CVSS 9.8 2025-03-07
Threat Entry Updated 2025-03-07

CVE-2025-1475 - Wpcom Member Plugin

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone' parameter when logging in. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if SMS login is enabled.

PLUGIN Wpcom Member

CVE-2025-1475

CRITICAL CVSS 9.8 2025-03-07
Threat Entry Updated 2025-03-05

CVE-2024-12281 - Homey Theme

The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the Editor or Shop Manager role.

THEME Homey

CVE-2024-12281

CRITICAL CVSS 9.8 2025-03-05
Scroll to top