Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 701-720 of 1249 records
Threat Entry Updated 2025-03-05

CVE-2024-11951 - Homey Login Register Plugin

The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.

PLUGIN Homey Login Register

CVE-2024-11951

CRITICAL CVSS 9.8 2025-03-05
Threat Entry Updated 2025-03-05

CVE-2025-1515 - Wp Real Estate Manager Plugin

The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.8. This is due to insufficient identity verification on the LinkedIn login request process. This makes it possible for unauthenticated attackers to bypass official authentication and log in as any user on the site, including administrators.

PLUGIN Wp Real Estate Manager

CVE-2025-1515

CRITICAL CVSS 9.8 2025-03-05
Threat Entry Updated 2025-03-05

CVE-2024-13787 - Veda Multipurpose Wordpress Theme

The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2 via deserialization of untrusted input in the 'veda_backup_and_restore_action' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin…

THEME Veda Multipurpose Wordpress Theme

CVE-2024-13787

CRITICAL CVSS 9.8 2025-03-05
Threat Entry Updated 2025-03-05

CVE-2025-1307 - Newscrunch Plugin

The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Newscrunch

CVE-2025-1307

CRITICAL CVSS 9.8 2025-03-04
Threat Entry Updated 2025-03-05

CVE-2025-0912 - Givewp Plugin

The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.

PLUGIN Givewp

CVE-2025-0912

CRITICAL CVSS 9.8 2025-03-04
Threat Entry Updated 2025-03-01

CVE-2025-1671 - Academist Membership Theme

The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as any user, including site administrators.

THEME Academist Membership

CVE-2025-1671

CRITICAL CVSS 9.8 2025-03-01
Threat Entry Updated 2025-03-01

CVE-2025-1638 - Alloggio Membership Theme

The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity through the alloggio_membership_init_rest_api_facebook_login and alloggio_membership_init_rest_api_google_login functions. This makes it possible for unauthenticated attackers to log in as any user, including administrators, without knowing a password.

THEME Alloggio Membership

CVE-2025-1638

CRITICAL CVSS 9.8 2025-03-01
Threat Entry Updated 2025-03-01

CVE-2025-1564 - SetSail Membership Theme

The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a users identity through the social login. This makes it possible for unauthenticated attackers to log in as any user, including administrators and take over access to their account.

THEME SetSail Membership

CVE-2025-1564

CRITICAL CVSS 9.8 2025-03-01
Threat Entry Updated 2025-03-01

CVE-2024-12824 - Job Board Wordpress Theme

The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.2. This is due to the plugin not properly checking for an empty token value prior updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's password, including administrators, and leverage that to gain access to their account.

THEME Job Board Wordpress Theme

CVE-2024-12824

CRITICAL CVSS 9.8 2025-03-01
Threat Entry Updated 2025-03-25

CVE-2024-9193 - Whmcs Plugin

The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.3-revision-0 via the whmpress_domain_search_ajax_extended_results() function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. This makes it possible for unauthenticated attackers…

PLUGIN Whmcs

CVE-2024-9193

CRITICAL CVSS 9.8 2025-02-28
Threat Entry Updated 2025-03-06

CVE-2024-8425 - Woocommerce Ultimate Gift Card Plugin

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.6.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Woocommerce Ultimate Gift Card

CVE-2024-8425

CRITICAL CVSS 9.8 2025-02-28
Threat Entry Updated 2025-03-06

CVE-2024-8420 - Dhvc Form Plugin

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites.

PLUGIN Dhvc Form

CVE-2024-8420

CRITICAL CVSS 9.8 2025-02-28
Threat Entry Updated 2025-02-28

CVE-2025-1128 - Everest Forms Plugin

The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including, 3.0.9.4. This makes it possible for unauthenticated attackers to upload, read, and delete arbitrary files on the affected site's server which may make remote code execution, sensitive information disclosure, or a site takeover possible.

PLUGIN Everest Forms

CVE-2025-1128

CRITICAL CVSS 9.8 2025-02-25
Threat Entry Updated 2025-02-25

CVE-2024-13789 - Ravpage Plugin

The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via deserialization of untrusted input from the 'paramsv2' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may…

PLUGIN Ravpage

CVE-2024-13789

CRITICAL CVSS 9.8 2025-02-20
Threat Entry Updated 2025-02-21

CVE-2024-12860 - Carspot Plugin

The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Carspot

CVE-2024-12860

CRITICAL CVSS 9.8 2025-02-18
Threat Entry Updated 2025-02-21

CVE-2024-13725 - Keap Official Opt In Forms Plugin

The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included. If register_argc_argv is enabled on the server and pearcmd.php is installed, this issue might lead…

PLUGIN Keap Official Opt In Forms

CVE-2024-13725

CRITICAL CVSS 9.8 2025-02-18
Threat Entry Updated 2025-02-24

CVE-2024-12562 - S2member Plugin

The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input from the 's2member_pro_remote_op' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN S2member

CVE-2024-12562

CRITICAL CVSS 9.8 2025-02-15
Threat Entry Updated 2025-02-25

CVE-2024-13513 - Oliver Pos Plugin

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2.3 via the logging functionality. This makes it possible for unauthenticated attackers to extract sensitive data including the plugin's clientToken, which in turn can be used to change user account information including emails and account type. This allows attackers to then change account passwords resulting in a complete site takeover. Version 2.4.2.3 disabled logging but left sites with existing log files vulnerable.

PLUGIN Oliver Pos

CVE-2024-13513

CRITICAL CVSS 9.8 2025-02-15
Threat Entry Updated 2025-02-13

CVE-2024-13182 - Wp Directorybox Manager Plugin

The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_parse_request' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator.

PLUGIN Wp Directorybox Manager

CVE-2024-13182

CRITICAL CVSS 9.8 2025-02-13
Threat Entry Updated 2025-11-13

CVE-2024-10763 - Campress Plugin

The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

PLUGIN Campress

CVE-2024-10763

CRITICAL CVSS 9.8 2025-02-13
Scroll to top