Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,857
Critical0
High0
Medium10,857
Reset
Showing 2121-2140 of 10857 records
Threat Entry Updated 2025-11-19

CVE-2025-12427 - Yith Woocommerce Wishlist Plugin

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST API endpoint and AJAX handler due to missing validation on user-controlled keys. This makes it possible for unauthenticated attackers to discover any user's wishlist token ID, and subsequently rename the victim's wishlist without authorization (integrity impact). This can be exploited to target multi-user stores for defacement, social engineering attacks, mass tampering, and profiling at scale.

PLUGIN Yith Woocommerce Wishlist

CVE-2025-12427

MEDIUM CVSS 5.3 2025-11-19
Threat Entry Updated 2025-11-19

CVE-2025-8084 - Ai Engine Plugin

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_create_images function. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. On Cloud instances, this issue allows for metadata retrieving.

PLUGIN Ai Engine

CVE-2025-8084

MEDIUM CVSS 6.8 2025-11-18
Threat Entry Updated 2025-11-19

CVE-2025-12376 - Icon List Block Plugin

The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.1 via the fs_api_request function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Only valid JSON objects are rendered in the response.

PLUGIN Icon List Block

CVE-2025-12376

MEDIUM CVSS 6.4 2025-11-18
Threat Entry Updated 2025-11-19

CVE-2025-12545 - Woocommerce Google Adwords Conversion Tracking Tag Plugin

The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.49.2 via the ajax_pmw_get_product_ids() function due to insufficient restrictions on which products can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft products that they should not have access to.

PLUGIN Woocommerce Google Adwords Conversion Tracking Tag

CVE-2025-12545

MEDIUM CVSS 5.3 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-11427 - Wp Migrate Db Plugin

The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.7.6 via the wpmdb_flush AJAX action. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to obtain information about internal services.

PLUGIN Wp Migrate Db

CVE-2025-11427

MEDIUM CVSS 5.8 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-13133 - A3 User Importer Plugin

The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.1.7 via the 'Import/export users' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration

PLUGIN A3 User Importer

CVE-2025-13133

MEDIUM CVSS 6.6 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-13196 - Element Pack Addons For Elementor Plugin

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Street Map widget's marker content parameter in all versions up to, and including, 8.3.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the render function. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack Addons For Elementor

CVE-2025-13196

MEDIUM CVSS 5.4 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-12691 - Others Plugin

The Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox functionality in all versions up to, and including, 3.21 due to insufficient input sanitization and output escaping on user supplied caption attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page.

PLUGIN Others

CVE-2025-12691

MEDIUM CVSS 6.4 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-12639 - Catalog Mode Pricing Enquiry Forms Promotions Plugin

The wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user is authorized to access sensitive information via the AJAX endpoint. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive information including user emails, usernames, roles, capabilities, and WooCommerce data such as products and payment methods.

PLUGIN Catalog Mode Pricing Enquiry Forms Promotions

CVE-2025-12639

MEDIUM CVSS 4.3 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-12457 - Enable Svg Webp Ico Upload Plugin

The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Enable Svg Webp Ico Upload

CVE-2025-12457

MEDIUM CVSS 6.4 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-12088 - Meta Display Block Plugin

The Meta Display Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meta Display Block in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Meta Display Block

CVE-2025-12088

MEDIUM CVSS 6.4 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-12392 - Triplea Cryptocurrency Payment Gateway For Woocommerce Plugin

The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_optin_optout' function in all versions up to, and including, 2.0.22. This makes it possible for unauthenticated attackers to opt in and out of tracking.

PLUGIN Triplea Cryptocurrency Payment Gateway For Woocommerce

CVE-2025-12392

MEDIUM CVSS 5.3 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-12391 - Bp Restrict Plugin

The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout() function in all versions up to, and including, 1.5.2. This makes it possible for unauthenticated attackers to opt in and out of tracking.

PLUGIN Bp Restrict

CVE-2025-12391

MEDIUM CVSS 5.3 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-12481 - Wp Duplicate Page Plugin

The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'saveSettings' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify plugin settings that control role capabilities, and subsequently exploit the misconfigured capabilities to duplicate and view password-protected posts containing sensitive information.

PLUGIN Wp Duplicate Page

CVE-2025-12481

MEDIUM CVSS 4.3 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-12079 - Twitter Auto Publish Plugin

The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Twitter Auto Publish

CVE-2025-12079

MEDIUM CVSS 6.1 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-11734 - Monitor Internal And External Links Plugin

The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization in all versions up to, and including, 1.2.5. This is due to the plugin registering a REST API endpoint that only checks for a broad capability (aioseo_blc_broken_links_page) that is granted to contributor level users, without verifying the user's permission to perform actions on the specific post being targeted. This makes it possible for authenticated attackers, with contributor level access and above, to trash arbitrary…

PLUGIN Monitor Internal And External Links

CVE-2025-11734

MEDIUM CVSS 5.4 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-8609 - Rometheme For Elementor Plugin

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion Block's attributes in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rometheme For Elementor

CVE-2025-8609

MEDIUM CVSS 6.4 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-8605 - Gutenify Plugin

The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenify

CVE-2025-8605

MEDIUM CVSS 6.4 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-9625 - Coil Web Monetization Plugin

The Coil Web Monetization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the coil-get-css-selector parameter handling in the maybe_restrict_content function. This makes it possible for unauthenticated attackers to trigger CSS selector detection functionality via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Coil Web Monetization

CVE-2025-9625

MEDIUM CVSS 4.3 2025-11-18
Threat Entry Updated 2025-11-18

CVE-2025-12937 - Acf Flexible Layouts Manager Plugin

The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'acf_flm_update_template_with_pasted_layout' function in all versions up to, and including, 1.1.6. This makes it possible for unauthenticated attackers to update custom field values on individual posts and pages.

PLUGIN Acf Flexible Layouts Manager

CVE-2025-12937

MEDIUM CVSS 6.5 2025-11-18
Scroll to top