Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 2901-2920 of 10866 records
Threat Entry Updated 2025-08-04

CVE-2025-8488 - Header Footer Elementor Plugin

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the compatibility option setting.

PLUGIN Header Footer Elementor

CVE-2025-8488

MEDIUM CVSS 4.3 2025-08-02
Threat Entry Updated 2025-08-25

CVE-2025-6722 - Login Security Plugin

The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5 via the bitfire_* directory that automatically gets created and stores potentially sensitive files without any access restrictions. This makes it possible for unauthenticated attackers to extract sensitive data from various files like config.ini, debug.log, and more when directory listing is enabled on the server and the ~/wp-content/plugins/index.php file is missing or ignored.

PLUGIN Login Security

CVE-2025-6722

MEDIUM CVSS 5.3 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8399 - Mmm Unity Loader Plugin

The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mmm Unity Loader

CVE-2025-8399

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8400 - Bee Quick Gallery Plugin

The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bee Quick Gallery

CVE-2025-8400

MEDIUM CVSS 6.1 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8391 - Magic Edge Lite Image Background Remover Plugin

The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Magic Edge Lite Image Background Remover

CVE-2025-8391

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-6832 - Tracking Employee Time Has Never Been Easier Plugin

The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Tracking Employee Time Has Never Been Easier

CVE-2025-6832

MEDIUM CVSS 6.1 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8317 - Custom Word Cloud Plugin

The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘angle’ parameter in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Custom Word Cloud

CVE-2025-8317

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8212 - Medical Addon For Elementor Plugin

The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter widget in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Medical Addon For Elementor

CVE-2025-8212

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8152 - Easy Sticky Sidebar Plugin

The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_cta_status' and 'change_sticky_sidebar_name' functions in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to update the status of a sticky and update the name displayed in the back-end WP CTA Dashboard.

PLUGIN Easy Sticky Sidebar

CVE-2025-8152

MEDIUM CVSS 5.3 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-6626 - Shortpixel Adaptive Images Plugin

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Shortpixel Adaptive Images

CVE-2025-6626

MEDIUM CVSS 4.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-4588 - 360 Sphere Images Plugin

The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN 360 Sphere Images

CVE-2025-4588

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8146 - Qi Addons For Elementor Plugin

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut Text widget in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Qi Addons For Elementor

CVE-2025-8146

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-12

CVE-2025-7694 - Woffice Plugin

The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_delete() function in all versions up to, and including, 5.4.26. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Woffice

CVE-2025-7694

MEDIUM CVSS 6.8 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-6228 - Sina Extension For Elementor Plugin

The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `Sina Posts`, `Sina Blog Post` and `Sina Table` widgets in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sina Extension For Elementor

CVE-2025-6228

MEDIUM CVSS 6.4 2025-08-01
Threat Entry Updated 2025-08-04

CVE-2025-4684 - No Coding Needed Plugin

The BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attributes of Image Carousel and Image Slider widgets in all versions up to, and including, 3.2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected…

PLUGIN No Coding Needed

CVE-2025-4684

MEDIUM CVSS 6.4 2025-08-01
Threat Entry Updated 2025-08-04

CVE-2025-7646 - Plus Addons For Elementor Page Builder Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom script parameter in all versions up to, and including, 6.3.10 even when the user does not have the unfiltered_html capability. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor Page Builder

CVE-2025-7646

MEDIUM CVSS 6.4 2025-08-01
Threat Entry Updated 2025-08-06

CVE-2025-5921 - Before 1 Plugin

The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.

PLUGIN Before 1

CVE-2025-5921

MEDIUM CVSS 5.8 2025-08-01
Threat Entry Updated 2025-08-04

CVE-2025-7845 - Elementor Widgets Plugin

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Google Maps and Image Hotspot widgets in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elementor Widgets

CVE-2025-7845

MEDIUM CVSS 6.4 2025-08-01
Threat Entry Updated 2025-12-05

CVE-2025-4523 - Idonate Plugin

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the admin_donor_profile_view() function in versions 2.0.0 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to expose an administrator’s username, email address, and all donor fields.

PLUGIN Idonate

CVE-2025-4523

MEDIUM CVSS 6.5 2025-08-01
Threat Entry Updated 2025-08-13

CVE-2025-8401 - Ht Mega Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including the content of private, password-protected, and draft posts and pages.

PLUGIN Ht Mega

CVE-2025-8401

MEDIUM CVSS 4.3 2025-07-31
Scroll to top