Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,044
Critical0
High3,044
Medium0
Reset
Showing 1241-1260 of 3044 records
Threat Entry Updated 2025-07-09

CVE-2025-1971 - Import Export Wordpress Users Plugin

The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional…

PLUGIN Import Export Wordpress Users

CVE-2025-1971

HIGH CVSS 7.2 2025-03-22
Threat Entry Updated 2025-07-09

CVE-2025-1970 - Import Export Wordpress Users Plugin

The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Import Export Wordpress Users

CVE-2025-1970

HIGH CVSS 7.6 2025-03-22
Threat Entry Updated 2025-03-22

CVE-2025-2303 - Block Logic – Full Gutenberg Block Display Control Plugin

The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 via the block_logic_check_logic function. This is due to the unsafe evaluation of user-controlled input. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

PLUGIN Block Logic – Full Gutenberg Block Display Control

CVE-2025-2303

HIGH CVSS 8.8 2025-03-22
Threat Entry Updated 2025-03-27

CVE-2025-0724 - Profilegrid Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted input in the get_user_meta_fields_html function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an…

PLUGIN Profilegrid

CVE-2025-0724

HIGH CVSS 8.8 2025-03-22
Threat Entry Updated 2025-08-11

CVE-2025-2539 - File Away Plugin

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN File Away

CVE-2025-2539

HIGH CVSS 7.5 2025-03-20
Threat Entry Updated 2025-03-26

CVE-2024-13923 - Order Export Order Import For Woocommerce Plugin

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Order Export Order Import For Woocommerce

CVE-2024-13923

HIGH CVSS 7.6 2025-03-20
Threat Entry Updated 2025-03-27

CVE-2024-13558 - Np Quote Request For Woocommerce Plugin

The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the content of quote requests.

PLUGIN Np Quote Request For Woocommerce

CVE-2024-13558

HIGH CVSS 7.5 2025-03-20
Threat Entry Updated 2025-03-26

CVE-2024-13921 - Order Export Order Import For Woocommerce Plugin

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an…

PLUGIN Order Export Order Import For Woocommerce

CVE-2024-13921

HIGH CVSS 7.2 2025-03-20
Threat Entry Updated 2025-07-08

CVE-2025-1770 - Eventin Plugin

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the 'style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Eventin

CVE-2025-1770

HIGH CVSS 8.8 2025-03-20
Threat Entry Updated 2025-04-08

CVE-2024-13881 - Linkmyposts Plugin

The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Linkmyposts

CVE-2024-13881

HIGH CVSS 7.1 2025-03-20
Threat Entry Updated 2025-04-08

CVE-2024-13880 - My Quota Plugin

The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN My Quota

CVE-2024-13880

HIGH CVSS 7.1 2025-03-20
Threat Entry Updated 2025-04-08

CVE-2024-13878 - Spotbot Plugin

The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Spotbot

CVE-2024-13878

HIGH CVSS 7.1 2025-03-20
Threat Entry Updated 2025-04-09

CVE-2024-13877 - Passbeemedia Web Push Notification Plugin

The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Passbeemedia Web Push Notification

CVE-2024-13877

HIGH CVSS 7.1 2025-03-20
Threat Entry Updated 2025-04-09

CVE-2024-13876 - Meintopf Plugin

The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Meintopf

CVE-2024-13876

HIGH CVSS 7.1 2025-03-20
Threat Entry Updated 2025-04-10

CVE-2024-13875 - Wp Pmanager Plugin

The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Wp Pmanager

CVE-2024-13875

HIGH CVSS 7.1 2025-03-20
Threat Entry Updated 2025-03-19

CVE-2024-13933 - Delivery Restaurant Directory Wordpress Theme

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, export_widget_settings, ajax_import_widget_data, foodbakery_var_settings_backup_generate, foodbakery_var_backup_file_restore, and theme_option_rest_all functions. This makes it possible for unauthenticated attackers to delete arbitrary files, update theme options, export widget options, import widget options, generate backups, restore backups, and reset theme options via a forged request granted they can trick a site administrator into performing an action such…

THEME Delivery Restaurant Directory Wordpress Theme

CVE-2024-13933

HIGH CVSS 8.8 2025-03-19
Threat Entry Updated 2025-03-19

CVE-2024-12920 - Delivery Restaurant Directory Wordpress Theme

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, export_widget_settings, ajax_import_widget_data, foodbakery_var_settings_backup_generate, foodbakery_var_backup_file_restore, and theme_option_rest_all functions in all versions up to, and including, 4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files, update theme options, export widget options, import widget options, generate backups, restore backups, and reset theme options.

THEME Delivery Restaurant Directory Wordpress Theme

CVE-2024-12920

HIGH CVSS 8.8 2025-03-19
Threat Entry Updated 2025-03-19

CVE-2024-13412 - Cozystay Theme

The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to execute arbitrary actions.

THEME Cozystay

CVE-2024-13412

HIGH CVSS 7.5 2025-03-19
Threat Entry Updated 2025-05-09

CVE-2025-1232 - Site Reviews Plugin

The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks

PLUGIN Site Reviews

CVE-2025-1232

HIGH CVSS 8.8 2025-03-19
Threat Entry Updated 2025-03-19

CVE-2024-12295 - Boombox Theme Extensions Plugin

The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is due to the plugin not properly validating a user's identity prior to updating their password through the 'boombox_ajax_reset_password' function. This makes it possible for authenticated attackers, with subscriber-level privileges and above, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Boombox Theme Extensions

CVE-2024-12295

HIGH CVSS 8.8 2025-03-19
Scroll to top