Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,857
Critical0
High0
Medium10,857
Reset
Showing 2221-2240 of 10857 records
Threat Entry Updated 2025-11-12

CVE-2025-11894 - Shelf Planner Plugin

The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to modify several of the plugin's settings like the ServerKey and LicenseKey.

PLUGIN Shelf Planner

CVE-2025-11894

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11891 - Shelf Planner Plugin

The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.0 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

PLUGIN Shelf Planner

CVE-2025-11891

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11886 - Ctl Arcade Lite Plugin

The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'ctl_arcade_lite_page_manage_games' page. This makes it possible for unauthenticated attackers to deactivate and activate arbitrary plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ctl Arcade Lite

CVE-2025-11886

MEDIUM CVSS 4.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11873 - Wp Bbcode Plugin

The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Bbcode

CVE-2025-11873

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11869 - Precise Columns Plugin

The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attribute in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input or escaping output when inserting the wrapper ID into the generated HTML. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Precise Columns

CVE-2025-11869

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11863 - My Geo Posts Free Plugin

The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode in all versions up to, and including, 1.2. This is due to the plugin not properly sanitizing user input or escaping output of the 'default' shortcode attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN My Geo Posts Free

CVE-2025-11863

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11860 - Ot Twitter Feed Plugin

The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in all versions up to, and including, 1.3.1. This is due to the plugin not properly sanitizing user input and output of the 'width' and 'height' parameters. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ot Twitter Feed

CVE-2025-11860

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11859 - Paypal Donation Shortcode Plugin

The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in all versions up to, and including, 0.1. This is due to the plugin not properly sanitizing user input and output of the 'title' and 'text' parameters. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Paypal Donation Shortcode

CVE-2025-11859

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11874 - Slippy Slider Responsive Touch Navigation Slider Plugin

The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slippy-slider' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slippy Slider Responsive Touch Navigation Slider

CVE-2025-11874

MEDIUM CVSS 5.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11856 - Eventbee Ticketing Widget Plugin

The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketwidget' shortcode in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input and output of several parameters. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Eventbee Ticketing Widget

CVE-2025-11856

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11829 - Five9 Live Chat Plugin

The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the [five9-chat] shortcode in all versions up to, and including, 1.1.2. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Five9 Live Chat

CVE-2025-11829

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11828 - Bnm Blocks Plugin

The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribute in the bnm-blocks/featured-posts-1 block in all versions up to, and including, 1.2.3. This is due to insufficient input sanitization and output escaping when using user-supplied values as HTML tag names. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bnm Blocks

CVE-2025-11828

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11822 - Wp Bootstrap Tabs Plugin

The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcode in all versions up to, and including, 1.0.4. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Bootstrap Tabs

CVE-2025-11822

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11821 - Woocommerce Products By Custom Tax Plugin

The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_products_custom_tax' shortcode in all versions up to, and including, 2.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Woocommerce Products By Custom Tax

CVE-2025-11821

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11805 - Skip To Timestamp Plugin

The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in all versions up to, and including, 1.4.4. This is due to insufficient input sanitization and output escaping on the 'time' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Skip To Timestamp

CVE-2025-11805

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11532 - Wisly Plugin

The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.0 due to missing validation on the 'wishlist_id' user controlled key. This makes it possible for unauthenticated attackers to remove and add items to other user's wishlists.

PLUGIN Wisly

CVE-2025-11532

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11129 - Include Fussball De Widgets Plugin

The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'type' parameters in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Include Fussball De Widgets

CVE-2025-11129

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12092 - Cyan Backup Plugin

The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' functionality in all versions up to, and including, 2.5.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Cyan Backup

CVE-2025-12092

MEDIUM CVSS 6.5 2025-11-08
Threat Entry Updated 2025-11-12

CVE-2025-12837 - Athemes Addons For Elementor Lite Plugin

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Action widget in versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping on user-supplied values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Athemes Addons For Elementor Lite

CVE-2025-12837

MEDIUM CVSS 6.4 2025-11-08
Threat Entry Updated 2025-11-12

CVE-2025-12643 - Saphali Liqpay For Donate Plugin

The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay' shortcode in all versions up to, and including, 1.0.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Saphali Liqpay For Donate

CVE-2025-12643

MEDIUM CVSS 6.4 2025-11-08
Scroll to top