Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,857
Critical0
High0
Medium10,857
Reset
Showing 2001-2020 of 10857 records
Threat Entry Updated 2025-12-01

CVE-2025-13737 - Nextend Facebook Connect Plugin

The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is due to missing or incorrect nonce validation on the 'unlinkUser' function. This makes it possible for unauthenticated attackers to unlink the user's social login via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Nextend Facebook Connect

CVE-2025-13737

MEDIUM CVSS 4.3 2025-11-28
Threat Entry Updated 2025-12-01

CVE-2025-12971 - File Manager Plugin

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'wcp_change_post_folder' function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to move arbitrary folder contents to arbitrary folders.

PLUGIN File Manager

CVE-2025-12971

MEDIUM CVSS 4.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-10476 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate several database fix actions. This only affects sites with premium activated.

PLUGIN Wp Fastest Cache

CVE-2025-10476

MEDIUM CVSS 4.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13381 - Ays Chatgpt Assistant Plugin

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files.

PLUGIN Ays Chatgpt Assistant

CVE-2025-13381

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13378 - Ays Chatgpt Assistant Plugin

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.0 via the ays_chatgpt_pinecone_upsert function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Ays Chatgpt Assistant

CVE-2025-13378

MEDIUM CVSS 6.5 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12584 - Quick View For Woocommerce Plugin

The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX endpoint due to insufficient restrictions on which products can be included. This makes it possible for unauthenticated attackers to extract data from private products that they should not have access to.

PLUGIN Quick View For Woocommerce

CVE-2025-12584

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13441 - Hide Category By User Role For Woocommerce Plugin

The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This is due to a missing capability check on the admin_init hook that executes wp_cache_flush(). This makes it possible for unauthenticated attackers to flush the site's object cache via forged requests, potentially degrading site performance.

PLUGIN Hide Category By User Role For Woocommerce

CVE-2025-13441

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13157 - Qode Wishlist For Woocommerce Plugin

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the 'qode_wishlist_for_woocommerce_wishlist_table_item_callback' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to update the public view of arbitrary wishlists.

PLUGIN Qode Wishlist For Woocommerce

CVE-2025-13157

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13525 - Wp Directory Kit Plugin

The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Directory Kit

CVE-2025-13525

MEDIUM CVSS 6.1 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12185 - Stafflist Plugin

The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Stafflist

CVE-2025-12185

MEDIUM CVSS 4.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13143 - Social Polls By Opinionstage Plugin

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.12.0. This is due to missing or insufficient nonce validation on the disconnect_account_action function. This makes it possible for unauthenticated attackers to disconnect the site from the Opinion Stage platform integration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Social Polls By Opinionstage

CVE-2025-13143

MEDIUM CVSS 4.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12123 - Customer Reviews Collector For Woocommerce Plugin

The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email-text' parameter in all versions up to, and including, 4.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Customer Reviews Collector For Woocommerce

CVE-2025-12123

MEDIUM CVSS 6.1 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12151 - Simple Folio Plugin

The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Folio

CVE-2025-12151

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12713 - Soundslides Plugin

The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Soundslides

CVE-2025-12713

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12712 - Shouty Plugin

The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up to, and including, 0.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shouty

CVE-2025-12712

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12670 - Wp Twitpic Plugin

The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Twitpic

CVE-2025-12670

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12666 - Google Drive Upload And Download Link Plugin

The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter of the 'atachfilegoogle' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Google Drive Upload And Download Link

CVE-2025-12666

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12649 - Sorttable Post Plugin

The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sorttablepost shortcode in all versions up to, and including, 4.2. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via mouse interaction.

PLUGIN Sorttable Post

CVE-2025-12649

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12579 - Reuters Direct Plugin

The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'logoff' action in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to reset the plugin's settings.

PLUGIN Reuters Direct

CVE-2025-12579

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12578 - Reuters Direct Plugin

The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the the 'class-reuters-direct-settings.php' page. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Reuters Direct

CVE-2025-12578

MEDIUM CVSS 4.3 2025-11-27
Scroll to top