Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,857
Critical0
High0
Medium10,857
Reset
Showing 2201-2220 of 10857 records
Threat Entry Updated 2025-11-12

CVE-2025-12644 - Nonaki Email Template Customizer Plugin

The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nonaki' shortcode in all versions up to, and including, 1.0.11. This is due to insufficient input sanitization and output escaping on user supplied custom field values that are retrieved and rendered by the shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Nonaki Email Template Customizer

CVE-2025-12644

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12590 - Yslider Plugin

The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 1.1. This is due to missing nonce verification on the content configuration page and insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages via a forged request granted they can trick an administrator into performing an action such as clicking on a link. The injected scripts will execute whenever a user accesses an injected page.

PLUGIN Yslider

CVE-2025-12590

MEDIUM CVSS 6.1 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12589 - Security Plugin

The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 0.5.3.5. This is due to missing nonce verification on the settings page and insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

PLUGIN Security

CVE-2025-12589

MEDIUM CVSS 6.1 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12632 - Randomquotr Plugin

The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Randomquotr

CVE-2025-12632

MEDIUM CVSS 5.5 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12631 - Squirrels Auto Inventory Plugin

The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Squirrels Auto Inventory

CVE-2025-12631

MEDIUM CVSS 4.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12588 - Usb Qr Code Scanner For Woocommerce Plugin

The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the settings page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

PLUGIN Usb Qr Code Scanner For Woocommerce

CVE-2025-12588

MEDIUM CVSS 4.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12021 - Wp Oauth Plugin

The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Oauth

CVE-2025-12021

MEDIUM CVSS 6.1 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12126 - The Total Book Project Plugin

The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0 via several functions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform several actions like moving/deleting/creating chapters in books that do not belong to them.

PLUGIN The Total Book Project

CVE-2025-12126

MEDIUM CVSS 5.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12538 - Fleet Plugin

The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Fleet

CVE-2025-12538

MEDIUM CVSS 4.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12526 - Private Google Calendars Plugin

The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pgc_remove' action in all versions up to, and including, 20250811. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the plugin's settings.

PLUGIN Private Google Calendars

CVE-2025-12526

MEDIUM CVSS 4.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12132 - Wp Custom Login Page Logo Plugin

The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.8.4. This is due to missing or incorrect nonce validation on the wpclpl_save functionality. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Custom Login Page Logo

CVE-2025-12132

MEDIUM CVSS 4.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12010 - Authors List Plugin

The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_List_Shortcode class. This makes it possible for authenticated attackers, with Contributor-level access and above, to call methods such as get_meta to extract sensitive user data including password hashes, email addresses, usernames, and activation keys via specially crafted shortcode attributes

PLUGIN Authors List

CVE-2025-12010

MEDIUM CVSS 6.5 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11999 - Add Multiple Marker Plugin

The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and amm_save_map_api() functions in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to update the map API and reset maps.

PLUGIN Add Multiple Marker

CVE-2025-11999

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11997 - Document Pro Elementor Plugin

The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.9. This is due to the plugin exposing sensitive Algolia API keys through the frontend JavaScript code via wp_localize_script without proper access restrictions. This makes it possible for unauthenticated attackers to view sensitive API keys in the page source, which could be leveraged to make unauthorized API calls to the configured Algolia search service.

PLUGIN Document Pro Elementor

CVE-2025-11997

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-12-22

CVE-2025-11996 - Find Unused Images Plugin

The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() functiosn in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to delete all of a site's attachments.

PLUGIN Find Unused Images

CVE-2025-11996

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12020 - Double The Donation Plugin

The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Double The Donation

CVE-2025-12020

MEDIUM CVSS 4.9 2025-11-11
Threat Entry Updated 2025-12-22

CVE-2025-12019 - Featured Image Plugin

The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Featured Image

CVE-2025-12019

MEDIUM CVSS 4.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11882 - Simple Donate Plugin

The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortcode in versions less than, or equal to, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Donate

CVE-2025-11882

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11988 - Crypto Plugin

The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the crypto_delete_json method with only a publicly-available nonce check. This makes it possible for unauthenticated attackers to delete specific JSON files matching the pattern *_pending.json within the wp-content/uploads/yak/ directory, causing data loss and denial of service for plugin workflows that rely on these artifacts.

PLUGIN Crypto

CVE-2025-11988

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11986 - Crypto Plugin

The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the register and savenft methods with only a publicly-available nonce check and no wallet signature verification. This makes it possible for unauthenticated attackers to set a site-wide global authentication state via a single transient, bypassing all access controls for ALL visitors to the site. The impact is complete bypass of [crypto-block] shortcode restrictions and page-level access controls,…

PLUGIN Crypto

CVE-2025-11986

MEDIUM CVSS 5.3 2025-11-11
Scroll to top