Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,857
Critical0
High0
Medium10,857
Reset
Showing 2041-2060 of 10857 records
Threat Entry Updated 2025-11-25

CVE-2025-12040 - Th Wishlist Plugin

The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.9 via several functions in class-th-wishlist-frontend.php due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to modify other user's wishlists

PLUGIN Th Wishlist

CVE-2025-12040

MEDIUM CVSS 6.5 2025-11-25
Threat Entry Updated 2025-11-25

CVE-2025-12032 - Zweb Social Mobile Plugin

The Zweb Social Mobile – Ứng Dụng Nút Gọi Mobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vithanhlam_zsocial_save_messager’, 'vithanhlam_zsocial_save_zalo', 'vithanhlam_zsocial_save_hotline', and 'vithanhlam_zsocial_save_contact' parameters in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Zweb Social Mobile

CVE-2025-12032

MEDIUM CVSS 4.4 2025-11-25
Threat Entry Updated 2025-11-25

CVE-2025-12025 - Easy Youtube Subscribe Plugin

The YouTube Subscribe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Easy Youtube Subscribe

CVE-2025-12025

MEDIUM CVSS 4.4 2025-11-25
Threat Entry Updated 2026-01-16

CVE-2025-13558 - Blog2social Plugin

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'deleteUserCcDraftPost' function in all versions up to, and including, 8.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the status of arbitrary posts to trash.

PLUGIN Blog2social

CVE-2025-13558

MEDIUM CVSS 5.4 2025-11-25
Threat Entry Updated 2025-11-25

CVE-2025-10646 - Search Exclude Plugin

The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capability check on the Base::get_rest_permission() method in all versions up to, and including, 2.5.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify plugin settings, such as adding arbitrary posts to the search exclusion list.

PLUGIN Search Exclude

CVE-2025-10646

MEDIUM CVSS 4.3 2025-11-25
Threat Entry Updated 2025-11-25

CVE-2025-10144 - Perfect Woocommerce Brands Plugin

The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attribute of the `products` shortcode in all versions up to, and including, 3.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Perfect Woocommerce Brands

CVE-2025-10144

MEDIUM CVSS 6.5 2025-11-24
Threat Entry Updated 2025-11-25

CVE-2025-12569 - Front Editor Plugin

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

PLUGIN Front Editor

CVE-2025-12569

MEDIUM CVSS 4.7 2025-11-24
Threat Entry Updated 2025-11-25

CVE-2025-12394 - Backup Migration Plugin

The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.

PLUGIN Backup Migration

CVE-2025-12394

MEDIUM CVSS 5.9 2025-11-24
Threat Entry Updated 2025-11-25

CVE-2025-12800 - Shortcodes Ultimate Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.4.5 via the su_shortcode_csv_table function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. If the 'Unsafe features' option is explicitly enabled by an administrator, this issue becomes exploitable by Contributor+ attackers

PLUGIN Shortcodes Ultimate

CVE-2025-12800

MEDIUM CVSS 6.4 2025-11-23
Threat Entry Updated 2025-11-25

CVE-2025-13318 - Booking Calendar Contact Form Plugin

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to arbitrarily confirm bookings and bypass payment requirements via the 'dex_bccf_ipn' parameter.

PLUGIN Booking Calendar Contact Form

CVE-2025-13318

MEDIUM CVSS 5.3 2025-11-22
Threat Entry Updated 2025-11-25

CVE-2025-13136 - Gsheetconnector For Ninja Forms Plugin

The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'njform-google-sheet-config ' page in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve information about the system.

PLUGIN Gsheetconnector For Ninja Forms

CVE-2025-13136

MEDIUM CVSS 4.3 2025-11-22
Threat Entry Updated 2025-11-25

CVE-2025-13317 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the plugin exposing an unauthenticated booking processing endpoint (cpabc_appointments_check_IPN_verification) that trusts attacker-supplied payment notifications without verifying their origin, authenticity, or requiring proper authorization checks. This makes it possible for unauthenticated attackers to arbitrarily confirm bookings and insert them into the live calendar via the 'cpabc_ipncheck' parameter, triggering administrative and customer notification emails and disrupting operations.

PLUGIN Appointment Booking Calendar

CVE-2025-13317

MEDIUM CVSS 5.3 2025-11-22
Threat Entry Updated 2025-12-04

CVE-2025-12877 - Idonate Plugin

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability check on the panding_blood_request_action() function in all versions up to, and including, 2.1.15. This makes it possible for unauthenticated attackers to delete arbitrary posts.

PLUGIN Idonate

CVE-2025-12877

MEDIUM CVSS 5.3 2025-11-22
Threat Entry Updated 2025-11-25

CVE-2025-12752 - Subscriptions Memberships For Paypal Plugin

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries that have not actually occurred.

PLUGIN Subscriptions Memberships For Paypal

CVE-2025-12752

MEDIUM CVSS 5.3 2025-11-22
Threat Entry Updated 2025-11-25

CVE-2025-11186 - Cookie Notice Plugin

The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookies_accepted shortcode in all versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cookie Notice

CVE-2025-11186

MEDIUM CVSS 6.4 2025-11-22
Threat Entry Updated 2025-11-25

CVE-2025-12747 - Tainacan Plugin

The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content without adequate protection. This makes it possible for unauthenticated attackers to extract potentially sensitive information from files that have been marked as private.

PLUGIN Tainacan

CVE-2025-12747

MEDIUM CVSS 5.3 2025-11-21
Threat Entry Updated 2025-11-21

CVE-2025-12935 - And Crm Solution Plugin

The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fluentcrm_content' shortcode in all versions up to, and including, 2.9.84 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN And Crm Solution

CVE-2025-12935

MEDIUM CVSS 6.4 2025-11-21
Threat Entry Updated 2025-11-26

CVE-2025-10054 - Wsdesk Plugin

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eh_crm_remove_agent' function in all versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to remove the role and capabilities of any user with an Administrator, WSDesk Supervisor, or WSDesk Agents role.

PLUGIN Wsdesk

CVE-2025-10054

MEDIUM CVSS 5.3 2025-11-21
Threat Entry Updated 2025-11-26

CVE-2025-10039 - Wsdesk Plugin

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.9 via the 'eh_crm_ticket_single_view_client' due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of all support tickets.

PLUGIN Wsdesk

CVE-2025-10039

MEDIUM CVSS 4.3 2025-11-21
Scroll to top