Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 721-740 of 1249 records
Threat Entry Updated 2025-02-20

CVE-2024-10960 - Brizy Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Brizy

CVE-2024-10960

CRITICAL CVSS 9.9 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13365 - Security Malware Scan Plugin

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Security Malware Scan

CVE-2024-13365

CRITICAL CVSS 9.8 2025-02-12
Threat Entry Updated 2025-02-20

CVE-2024-12213 - Superio Plugin

The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites.

PLUGIN Superio

CVE-2024-12213

CRITICAL CVSS 9.8 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13421 - Real Estate 7 Plugin

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.

PLUGIN Real Estate 7

CVE-2024-13421

CRITICAL CVSS 9.8 2025-02-12
Threat Entry Updated 2025-02-11

CVE-2025-0181 - Wp Foodbakery Plugin

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.7. This is due to the plugin not properly validating a user's identity prior to setting the current user and their authentication cookie. This makes it possible for unauthenticated attackers to gain access to a target user's (e.g. administrators) account.

PLUGIN Wp Foodbakery

CVE-2025-0181

CRITICAL CVSS 9.8 2025-02-11
Threat Entry Updated 2025-02-11

CVE-2025-0180 - Wp Foodbakery Plugin

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator.

PLUGIN Wp Foodbakery

CVE-2025-0180

CRITICAL CVSS 9.8 2025-02-11
Threat Entry Updated 2025-02-10

CVE-2024-13011 - Wp Foodbakery Plugin

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wp Foodbakery

CVE-2024-13011

CRITICAL CVSS 9.8 2025-02-10
Threat Entry Updated 2025-02-08

CVE-2025-0316 - Wp Directorybox Manager Plugin

The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_enquiry_agent_contact_form_submit_callback' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

PLUGIN Wp Directorybox Manager

CVE-2025-0316

CRITICAL CVSS 9.8 2025-02-08
Threat Entry Updated 2025-02-07

CVE-2025-1061 - Nextend Social Login Pro Plugin

The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.16. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

PLUGIN Nextend Social Login Pro

CVE-2025-1061

CRITICAL CVSS 9.8 2025-02-07
Threat Entry Updated 2025-05-23

CVE-2025-0493 - Multivendorx Plugin

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the tabname parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included

PLUGIN Multivendorx

CVE-2025-0493

CRITICAL CVSS 9.8 2025-01-31
Threat Entry Updated 2025-01-30

CVE-2024-13742 - Icontrolwp Plugin

The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.5 via deserialization of untrusted input from the reqpars parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on…

PLUGIN Icontrolwp

CVE-2024-13742

CRITICAL CVSS 9.8 2025-01-30
Threat Entry Updated 2025-02-28

CVE-2024-12822 - Media Manager Plugin

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the add_capto_img() function in all versions up to, and including, 3.11.0. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

PLUGIN Media Manager

CVE-2024-12822

CRITICAL CVSS 9.8 2025-01-30
Threat Entry Updated 2025-01-30

CVE-2024-13448 - Addons Plugin

The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions up to, and including, 2.32.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Addons

CVE-2024-13448

CRITICAL CVSS 9.8 2025-01-28
Threat Entry Updated 2025-06-27

CVE-2025-0357 - Wpbookit Plugin

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::handle_image_upload' function in versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wpbookit

CVE-2025-0357

CRITICAL CVSS 9.8 2025-01-25
Threat Entry Updated 2025-02-05

CVE-2024-13545 - Ultimate Bootstrap Elements For Elementor Plugin

The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included. If php://filter is enabled on the server, this issue may directly lead to Remote Code Execution.

PLUGIN Ultimate Bootstrap Elements For Elementor

CVE-2024-13545

CRITICAL CVSS 9.8 2025-01-24
Threat Entry Updated 2025-01-22

CVE-2025-23931 - WordPress Local SEO Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WordPress Local SEO allows Blind SQL Injection. This issue affects WordPress Local SEO: from n/a through 2.3.

PLUGIN WordPress Local SEO

CVE-2025-23931

CRITICAL CVSS 9.3 2025-01-22
Threat Entry Updated 2025-01-24

CVE-2024-12857 - Adforest Plugin

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number.

PLUGIN Adforest

CVE-2024-12857

CRITICAL CVSS 9.8 2025-01-22
Threat Entry Updated 2025-01-24

CVE-2024-13091 - Wpot Plugin

The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qcld_wpcfb_file_upload' function in all versions up to, and including, 13.5.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit requires thee ChatBot Conversational Forms plugin and the Conversational Form Builder Pro addon plugin.

PLUGIN Wpot

CVE-2024-13091

CRITICAL CVSS 9.8 2025-01-22
Threat Entry Updated 2025-01-18

CVE-2024-13375 - Adifier System Plugin

The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.1.7. This is due to the plugin not properly validating a user's identity prior to updating their details like password through the adifier_recover() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Adifier System

CVE-2024-13375

CRITICAL CVSS 9.8 2025-01-18
Threat Entry Updated 2025-01-15

CVE-2024-9636 - Post Grid Plugin

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator.

PLUGIN Post Grid

CVE-2024-9636

CRITICAL CVSS 9.8 2025-01-15
Scroll to top