Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,040
Critical0
High3,040
Medium0
Reset
Showing 841-860 of 3040 records
Threat Entry Updated 2025-10-06

CVE-2025-9561 - Ap Background Plugin

The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insufficient file validation within the advParallaxBackAdminSaveSlider() handler in versions 3.8.1 to 3.8.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Ap Background

CVE-2025-9561

HIGH CVSS 8.8 2025-10-03
Threat Entry Updated 2025-10-06

CVE-2025-9213 - Textbuilder Plugin

The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due to missing or incorrect nonce validation on the 'handleToken' function. This makes it possible for unauthenticated attackers to update a user's authorization token via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Once the token is updated, an attacker can update the user's password and email address.

PLUGIN Textbuilder

CVE-2025-9213

HIGH CVSS 8.8 2025-10-03
Threat Entry Updated 2025-10-06

CVE-2025-9212 - Wp Dispatcher Plugin

The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wp_dispatcher_process_upload() function in all versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The directory does have an .htaccess file which limits the ability to achieve remote code execution.

PLUGIN Wp Dispatcher

CVE-2025-9212

HIGH CVSS 7.5 2025-10-03
Threat Entry Updated 2025-10-06

CVE-2025-9200 - Yournewsapp Plugin

The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to SQL Injection via the nh_ynaa_comments() function in all versions up to, and including, 0.8.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Yournewsapp

CVE-2025-9200

HIGH CVSS 7.5 2025-10-03
Threat Entry Updated 2025-10-06

CVE-2025-10582 - Wp Dispatcher Plugin

The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Dispatcher

CVE-2025-10582

HIGH CVSS 8.8 2025-10-03
Threat Entry Updated 2025-11-13

CVE-2025-9587 - Ctl Behance Importer Lite Plugin

The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

PLUGIN Ctl Behance Importer Lite

CVE-2025-9587

HIGH CVSS 8.6 2025-10-02
Threat Entry Updated 2025-10-02

CVE-2025-9993 - Bei Fen Plugin

The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the 'task'. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. This only affects instances running…

PLUGIN Bei Fen

CVE-2025-9993

HIGH CVSS 8.1 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-9991 - Tiny Bootstrap Elements Light Plugin

The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

PLUGIN Tiny Bootstrap Elements Light

CVE-2025-9991

HIGH CVSS 8.1 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-8877 - Affiliatewp Plugin

The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in all versions up to, and including, 2.28.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Affiliatewp

CVE-2025-8877

HIGH CVSS 7.5 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-7052 - Latepoint Plugin

The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.94. This is due to missing nonce validation on the change_password() function of its customer_cabinet__change_password AJAX route. The plugin hooks this endpoint via wp_ajax and wp_ajax_nopriv but does not verify a nonce or user capability before resetting the user’s password. This makes it possible for unauthenticated attackers who trick a logged-in customer (or, with “WP users as customers” enabled, an administrator) into visiting a malicious link to take over their account.

PLUGIN Latepoint

CVE-2025-7052

HIGH CVSS 8.8 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-7038 - Latepoint Plugin

The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification within the steps__load_step route of the latepoint_route_call AJAX endpoint in all versions up to, and including, 5.1.94. The endpoint reads the client-supplied customer email and related customer fields before invoking the internal login handler without verifying login status, capability checks, or a valid AJAX nonce. This makes it possible for unauthenticated attackers to log into any customer’s account.

PLUGIN Latepoint

CVE-2025-7038

HIGH CVSS 8.2 2025-09-30
Threat Entry Updated 2025-09-29

CVE-2025-9816 - Wp Statistics Plugin

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all versions up to, and including, 14.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Statistics

CVE-2025-9816

HIGH CVSS 7.2 2025-09-27
Threat Entry Updated 2025-09-26

CVE-2025-10747 - Wp Downloadmanager Plugin

The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file in all versions up to, and including, 1.68.11. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wp Downloadmanager

CVE-2025-10747

HIGH CVSS 7.2 2025-09-26
Threat Entry Updated 2025-09-24

CVE-2025-10380 - Acf Views Plugin

The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template Injection in all versions up to, and including, 3.7.19. This is due to insufficient input sanitization and lack of access control when processing custom Twig templates in the Model panel. This makes it possible for authenticated attackers, with author-level access or higher, to execute arbitrary PHP code and commands on the server.

PLUGIN Acf Views

CVE-2025-10380

HIGH CVSS 8.8 2025-09-23
Threat Entry Updated 2025-09-22

CVE-2025-57977 - WooCommerce Plugin

Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress allows Cross Site Request Forgery. This issue affects Flexible PDF Invoices for WooCommerce & WordPress: from n/a through 6.0.13.

PLUGIN WooCommerce

CVE-2025-57977

HIGH CVSS 7.1 2025-09-22
Threat Entry Updated 2025-09-22

CVE-2025-57919 - WordPress Core

Deserialization of Untrusted Data vulnerability in ConveyThis Language Translate Widget for WordPress – ConveyThis allows Object Injection. This issue affects Language Translate Widget for WordPress – ConveyThis: from n/a through 264.

CORE WordPress Core

CVE-2025-57919

HIGH CVSS 7.2 2025-09-22
Threat Entry Updated 2025-09-19

CVE-2025-7665 - Miniorange Firebase Sms Otp Verification Plugin

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premium features must be enabled in order to exploit the vulnerability.

PLUGIN Miniorange Firebase Sms Otp Verification

CVE-2025-7665

HIGH CVSS 8.1 2025-09-19
Threat Entry Updated 2025-09-19

CVE-2025-10647 - Embed Pdf Wpforms Plugin

The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_handler_download_pdf_media function in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Embed Pdf Wpforms

CVE-2025-10647

HIGH CVSS 8.8 2025-09-19
Threat Entry Updated 2025-09-19

CVE-2025-5955 - Service Finder Sms System Plugin

The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugin not verifying a user's phone number before logging them in. This makes it possible for unauthenticated attackers to login as arbitrary users.

PLUGIN Service Finder Sms System

CVE-2025-5955

HIGH CVSS 8.1 2025-09-19
Threat Entry Updated 2025-09-18

CVE-2025-8565 - Wp Legal Pages Plugin

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the wplp_gdpr_install_plugin_ajax_handler() function in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to install arbitrary repository plugins.

PLUGIN Wp Legal Pages

CVE-2025-8565

HIGH CVSS 8.1 2025-09-18
Scroll to top