Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,044
Critical0
High3,044
Medium0
Reset
Showing 1221-1240 of 3044 records
Threat Entry Updated 2025-08-12

CVE-2025-2328 - Drag And Drop Multiple File Upload Contact Form 7 Plugin

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'dnd_remove_uploaded_files' function in all versions up to, and including, 1.3.8.7. This makes it possible for unauthenticated attackers to add arbitrary file paths (such as ../../../../wp-config.php) to uploaded files on the server, which can easily lead to remote code execution when an Administrator deletes the message. Exploiting this vulnerability requires the Flamingo plugin to be installed and activated.

PLUGIN Drag And Drop Multiple File Upload Contact Form 7

CVE-2025-2328

HIGH CVSS 8.8 2025-03-28
Threat Entry Updated 2025-08-12

CVE-2025-2485 - Drag And Drop Multiple File Upload Contact Form 7 Plugin

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted input from the 'dnd_upload_cf7_upload' function. This makes it possible for attackers to inject a PHP Object through a PHAR file. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via…

PLUGIN Drag And Drop Multiple File Upload Contact Form 7

CVE-2025-2485

HIGH CVSS 7.5 2025-03-28
Threat Entry Updated 2025-03-27

CVE-2025-28928 - Are you robot google recaptcha for wordpress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sureshdsk Are you robot google recaptcha for wordpress allows Reflected XSS. This issue affects Are you robot google recaptcha for wordpress: from n/a through 2.2.

PLUGIN Are you robot google recaptcha for wordpress

CVE-2025-28928

HIGH CVSS 7.1 2025-03-26
Threat Entry Updated 2025-08-11

CVE-2025-2110 - Wp Compress Plugin

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its AJAX functions in all versions up to, and including, 6.30.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to compromise the site in various ways depending on the specific function exploited - for example, by retrieving sensitive settings and configuration details, or by altering and deleting them, thereby disclosing sensitive information, disrupting the plugin’s functionality,…

PLUGIN Wp Compress

CVE-2025-2110

HIGH CVSS 8.8 2025-03-26
Threat Entry Updated 2025-07-09

CVE-2025-1912 - Product Import Export For Woocommerce Plugin

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the validate_file() Function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Product Import Export For Woocommerce

CVE-2025-1912

HIGH CVSS 7.6 2025-03-26
Threat Entry Updated 2025-12-05

CVE-2025-1913 - Product Import Export For Woocommerce Plugin

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via deserialization of untrusted input from the 'form_data' parameter This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain…

PLUGIN Product Import Export For Woocommerce

CVE-2025-1913

HIGH CVSS 7.2 2025-03-26
Threat Entry Updated 2025-03-27

CVE-2024-13889 - Wordpress Importer Plugin

The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of untrusted input in the 'maybe_unserialize' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed…

PLUGIN Wordpress Importer

CVE-2024-13889

HIGH CVSS 7.2 2025-03-26
Threat Entry Updated 2025-05-22

CVE-2025-2257 - Total Upkeep Plugin

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using the compression_level setting in proc_open() without any validation. This makes it possible for authenticated attackers, with administrator-level access and above, to execute code on the server.

PLUGIN Total Upkeep

CVE-2025-2257

HIGH CVSS 7.2 2025-03-26
Threat Entry Updated 2025-03-27

CVE-2025-2009 - Newsletters Plugin

The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logging functionality in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Newsletters

CVE-2025-2009

HIGH CVSS 7.2 2025-03-26
Threat Entry Updated 2025-03-27

CVE-2024-13801 - Bwl Advanced Faq Manager Plugin

The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'baf_set_notice_status' AJAX action in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to '1' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to…

PLUGIN Bwl Advanced Faq Manager

CVE-2024-13801

HIGH CVSS 8.1 2025-03-26
Threat Entry Updated 2025-03-27

CVE-2025-1514 - Active Products Tables for WooCommerce. Use constructor to create tables Plugin

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized filter calling due to insufficient restrictions on the get_smth() function in all versions up to, and including, 1.0.6.7. This makes it possible for unauthenticated attackers to call arbitrary WordPress filters with a single parameter.

PLUGIN Active Products Tables for WooCommerce. Use constructor to create tables

CVE-2025-1514

HIGH CVSS 7.3 2025-03-26
Threat Entry Updated 2025-04-30

CVE-2024-13146 - Before 4 Plugin

The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack

PLUGIN Before 4

CVE-2024-13146

HIGH CVSS 8.8 2025-03-26
Threat Entry Updated 2025-03-27

CVE-2025-2319 - Ez Sql Reports Shortcode Widget And Db Backup Plugin

The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.11.13 to 5.25.08. This is due to missing or incorrect nonce validation on the 'ELISQLREPORTS_menu' function. This makes it possible for unauthenticated attackers to execute code on the server via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Version 5.25.10 adds a nonce check, which makes this vulnerability exploitable by admins only.

PLUGIN Ez Sql Reports Shortcode Widget And Db Backup

CVE-2025-2319

HIGH CVSS 8.8 2025-03-25
Threat Entry Updated 2025-03-27

CVE-2024-13690 - Wp Church Donation Plugin

The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submission parameters in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Church Donation

CVE-2024-13690

HIGH CVSS 7.2 2025-03-25
Threat Entry Updated 2025-04-29

CVE-2024-13863 - Before 4 Plugin

The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 4

CVE-2024-13863

HIGH CVSS 7.1 2025-03-25
Threat Entry Updated 2025-03-22

CVE-2025-2186 - FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce Plugin

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the ‘automationId’ parameter in all versions up to, and including, 3.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

CVE-2025-2186

HIGH CVSS 7.5 2025-03-22
Scroll to top