Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,857
Critical0
High0
Medium10,857
Reset
Showing 2181-2200 of 10857 records
Threat Entry Updated 2025-11-12

CVE-2025-12833 - Geodirectory Plugin

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to attach arbitrary image files to arbitrary places.

PLUGIN Geodirectory

CVE-2025-12833

MEDIUM CVSS 4.3 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12087 - Wishlist And Save For Later For Woocommerce Plugin

The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.22 via the 'awwlm_remove_added_wishlist_page' AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete wishlist items from other user's wishlists.

PLUGIN Wishlist And Save For Later For Woocommerce

CVE-2025-12087

MEDIUM CVSS 4.3 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12953 - Business Directory Plugin

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "rtcl_ajax_add_listing_type", "rtcl_ajax_update_listing_type", and "rtcl_ajax_delete_listing_type" function in all versions up to, and including, 5.2.0. This makes it possible for authenticated attackers, with subscriber level access and above, to add, update, or delete listing types.

PLUGIN Business Directory

CVE-2025-12953

MEDIUM CVSS 4.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12788 - Booking Calendar Plugin

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment verification to unauthenticated payment bypass in all versions up to, and including, 1.1.27. This is due to the plugin accepting client-controlled payment confirmation data in the tfhb_meeting_paypal_payment_confirmation_callback function without server-side verification with PayPal's API. This makes it possible for unauthenticated attackers to bypass payment requirements and confirm bookings as paid without any actual payment transaction occurring.

PLUGIN Booking Calendar

CVE-2025-12788

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12787 - Booking Calendar Plugin

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's "tfhb_meeting_form_submit_callback" function using insufficiently random values to generate booking cancellation tokens, combined with a globally shared nonce. This makes it possible for unauthenticated attackers to cancel arbitrary bookings via brute force attacks against the tfhb_meeting_form_cencel AJAX endpoint.

PLUGIN Booking Calendar

CVE-2025-12787

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11237 - Make Email Customizer For Woocommerce Plugin

The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options.

PLUGIN Make Email Customizer For Woocommerce

CVE-2025-11237

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12754 - Geopost Plugin

The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost' shortcode in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Geopost

CVE-2025-12754

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12753 - Chart Expert Plugin

The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Chart Expert

CVE-2025-12753

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12880 - Progressmatify Blocks Plugin

The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Progressmatify Blocks

CVE-2025-12880

MEDIUM CVSS 5.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12711 - Share To Google Classroom Plugin

The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Share To Google Classroom

CVE-2025-12711

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12672 - Wp Flickrshow Plugin

The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'div_height' parameter of the 'flickrshow' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Flickrshow

CVE-2025-12672

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12671 - Wp Iconics Plugin

The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_iconics' shortcode in all versions up to, and including, 0.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Iconics

CVE-2025-12671

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12668 - Wp Count Down Timer Plugin

The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Count Down Timer

CVE-2025-12668

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12667 - Github Gist Shortcode Plugin

The GitHub Gist Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'gist' shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Github Gist Shortcode

CVE-2025-12667

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12665 - Ninja Countdown Plugin

The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ninja_countdown_admin_ajax' AJAX endpoint in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary countdowns.

PLUGIN Ninja Countdown

CVE-2025-12665

MEDIUM CVSS 4.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12663 - Jeba Cute Forkit Plugin

The Jeba Cute forkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter in the 'jeba_forkit' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Jeba Cute Forkit

CVE-2025-12663

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12662 - Coon Google Maps Plugin

The Coon Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the 'map' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Coon Google Maps

CVE-2025-12662

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12658 - Preload Current Images Plugin

The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' parameter in the 'preload_progress_bar' shortcode in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Preload Current Images

CVE-2025-12658

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12652 - Ungapped Widgets Plugin

The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prefillvalues' parameter in the ungapped-form shortcode in all versions up to, and including, 1. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute when a user accesses an injected page.

PLUGIN Ungapped Widgets

CVE-2025-12652

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12651 - Live Photos Plugin

The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img_src', and 'class' parameters in the livephotos_photo shortcode in all versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute when a user accesses an injected page.

PLUGIN Live Photos

CVE-2025-12651

MEDIUM CVSS 6.4 2025-11-11
Scroll to top