Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,863
Critical0
High0
Medium10,863
Reset
Showing 2601-2620 of 10863 records
Threat Entry Updated 2025-10-02

CVE-2025-10191 - Woo Bigpost Shipping Plugin

The Big Post Shipping for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wooboigpost_shipping_status' shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Woo Bigpost Shipping

CVE-2025-10191

MEDIUM CVSS 6.4 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-10189 - Bp Direct Menus Plugin

The BP Direct Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bpdm_login' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bp Direct Menus

CVE-2025-10189

MEDIUM CVSS 6.4 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-10182 - Dbview Plugin

The dbview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dbview' shortcode in all versions up to, and including, 0.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Dbview

CVE-2025-10182

MEDIUM CVSS 6.4 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-10179 - My Askai Plugin

The My AskAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'myaskai' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN My Askai

CVE-2025-10179

MEDIUM CVSS 6.4 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-10168 - Any News Ticker Plugin

The Any News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'any-ticker' shortcode in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Any News Ticker

CVE-2025-10168

MEDIUM CVSS 6.4 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-10131 - All Social Share Options Plugin

The All Social Share Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sc' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN All Social Share Options

CVE-2025-10131

MEDIUM CVSS 6.4 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-10130 - Layers Plugin

The Layers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all versions up to, and including, 0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Layers

CVE-2025-10130

MEDIUM CVSS 6.4 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-10128 - Alleaktien Quantitativ Plugin

The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aaq' shortcode in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Alleaktien Quantitativ

CVE-2025-10128

MEDIUM CVSS 6.4 2025-09-30
Threat Entry Updated 2025-10-02

CVE-2025-10000 - Qyrr Code Plugin

The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the blob_to_file() function in all versions up to, and including, 2.0.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Qyrr Code

CVE-2025-10000

MEDIUM CVSS 6.4 2025-09-30
Threat Entry Updated 2025-11-13

CVE-2024-5200 - Before 1 Plugin

The Postie WordPress plugin before 1.9.71 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-5200

MEDIUM CVSS 4.8 2025-09-29
Threat Entry Updated 2025-09-29

CVE-2025-9899 - Trust Reviews Plugin

The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the feed_save function. This makes it possible for unauthenticated attackers to create or modify feed entries via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Trust Reviews

CVE-2025-9899

MEDIUM CVSS 6.1 2025-09-27
Threat Entry Updated 2025-09-29

CVE-2025-9944 - Professional Contact Form Plugin

The Professional Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the watch_for_contact_form_submit function. This makes it possible for unauthenticated attackers to trigger test email sending via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Professional Contact Form

CVE-2025-9944

MEDIUM CVSS 4.3 2025-09-27
Threat Entry Updated 2025-09-29

CVE-2025-9898 - Light Speed Fast Form Builder Plugin

The cForms – Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the cforms_api function. This makes it possible for unauthenticated attackers to modify forms and their settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Light Speed Fast Form Builder

CVE-2025-9898

MEDIUM CVSS 4.3 2025-09-27
Threat Entry Updated 2025-09-29

CVE-2025-9896 - Hidepost Plugin

The HidePost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.8. This is due to missing or incorrect nonce validation on the options.php settings page. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Hidepost

CVE-2025-9896

MEDIUM CVSS 4.3 2025-09-27
Threat Entry Updated 2025-09-29

CVE-2025-9894 - Sync Feedly Plugin

The Sync Feedly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the crsf_cron_job_func function. This makes it possible for unauthenticated attackers to trigger content synchronization from Feedly, potentially creating multiple posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Sync Feedly

CVE-2025-9894

MEDIUM CVSS 4.3 2025-09-27
Threat Entry Updated 2025-09-29

CVE-2025-9893 - Vm Menu Reorder Plugin

The VM Menu Reorder plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the vm_set_to_default function. This makes it possible for unauthenticated attackers to reset all menu reordering settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Vm Menu Reorder

CVE-2025-9893

MEDIUM CVSS 4.3 2025-09-27
Threat Entry Updated 2025-12-23

CVE-2025-10499 - Ninja Forms Plugin

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt an affected site into usage statistics collection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ninja Forms

CVE-2025-10499

MEDIUM CVSS 4.3 2025-09-27
Threat Entry Updated 2025-12-23

CVE-2025-10498 - Ninja Forms Plugin

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those files granted they can trick an administrator into performing an action such as clicking on a link.

PLUGIN Ninja Forms

CVE-2025-10498

MEDIUM CVSS 4.3 2025-09-27
Threat Entry Updated 2025-09-29

CVE-2025-8440 - Team Members Plugin

The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Team Members

CVE-2025-8440

MEDIUM CVSS 6.4 2025-09-27
Threat Entry Updated 2025-09-26

CVE-2025-10490 - Zephyr Project Manager Plugin

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.202 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Zephyr Project Manager

CVE-2025-10490

MEDIUM CVSS 4.4 2025-09-26
Scroll to top