Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 3001-3020 of 10866 records
Threat Entry Updated 2025-07-22

CVE-2025-7660 - Map My Locations Plugin

The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_locations' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Map My Locations

CVE-2025-7660

MEDIUM CVSS 6.4 2025-07-18
Threat Entry Updated 2025-07-22

CVE-2025-7648 - Ruven Themes Shortcodes Plugin

The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_button' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ruven Themes Shortcodes

CVE-2025-7648

MEDIUM CVSS 6.4 2025-07-18
Threat Entry Updated 2025-07-22

CVE-2025-7638 - Custom Form Builder Plugin

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Custom Form Builder

CVE-2025-7638

MEDIUM CVSS 4.9 2025-07-18
Threat Entry Updated 2025-07-22

CVE-2025-6053 - Zuppler Online Ordering Plugin

The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the 'zuppler-online-ordering-options' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Zuppler Online Ordering

CVE-2025-6053

MEDIUM CVSS 6.1 2025-07-18
Threat Entry Updated 2025-07-22

CVE-2025-6781 - Copymatic Plugin

The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the 'copymatic-menu' page. This makes it possible for unauthenticated attackers to update the copymatic_apikey option via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Copymatic

CVE-2025-6781

MEDIUM CVSS 4.3 2025-07-18
Threat Entry Updated 2025-07-22

CVE-2025-5816 - Biteship Plugin

The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.0 via the get_order_detail() due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view other user's orders.

PLUGIN Biteship

CVE-2025-5816

MEDIUM CVSS 4.3 2025-07-18
Threat Entry Updated 2025-07-22

CVE-2025-7431 - Knowledge Base Plugin

The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Knowledge Base

CVE-2025-7431

MEDIUM CVSS 4.4 2025-07-18
Threat Entry Updated 2026-01-23

CVE-2025-4302 - Stop User Enumeration Plugin

The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.

PLUGIN Stop User Enumeration

CVE-2025-4302

MEDIUM CVSS 5.3 2025-07-17
Threat Entry Updated 2025-07-16

CVE-2025-48294 - WordPress Core

Server-Side Request Forgery (SSRF) vulnerability in Kerfred FG Drupal to WordPress allows Server Side Request Forgery. This issue affects FG Drupal to WordPress: from n/a through 3.90.0.

CORE WordPress Core

CVE-2025-48294

MEDIUM CVSS 4.4 2025-07-16
Threat Entry Updated 2025-07-23

CVE-2025-7035 - Media Library Assistant Plugin

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_cloud and mla_term_list shortcodes in all versions up to, and including, 3.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Media Library Assistant

CVE-2025-7035

MEDIUM CVSS 6.4 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-5284 - Master Addons Plugin

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS extension in all versions up to, and including, 2.0.8.2 due to insufficient capability restriction, and insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Master Addons

CVE-2025-5284

MEDIUM CVSS 6.4 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-6747 - Builder Plugin

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusion_map' shortcode in all versions up to, and including, 3.12.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Builder

CVE-2025-6747

MEDIUM CVSS 6.4 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-5845 - Affiliate Reviews Plugin

The Affiliate Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘numColumns’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Affiliate Reviews

CVE-2025-5845

MEDIUM CVSS 6.4 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-5843 - Brandfolder Plugin

The Brandfolder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 5.0.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Brandfolder

CVE-2025-5843

MEDIUM CVSS 6.4 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-2799 - Wp Event Manager Plugin

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tag-name’ parameter in all versions up to, and including, 3.1.49 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Wp Event Manager

CVE-2025-2799

MEDIUM CVSS 4.4 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-6977 - Profilegrid Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in all versions up to, and including, 5.9.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a logged-in user into performing an action such as clicking on a link.

PLUGIN Profilegrid

CVE-2025-6977

MEDIUM CVSS 6.1 2025-07-16
Threat Entry Updated 2025-07-15

CVE-2025-4369 - Companion Auto Update Plugin

The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days’ parameter in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Companion Auto Update

CVE-2025-4369

MEDIUM CVSS 5.5 2025-07-15
Threat Entry Updated 2025-07-15

CVE-2025-7367 - Strong Testimonials Plugin

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fields in all versions up to, and including, 3.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Strong Testimonials

CVE-2025-7367

MEDIUM CVSS 6.4 2025-07-15
Threat Entry Updated 2025-07-29

CVE-2021-4458 - Modern Events Calendar Lite Plugin

The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX action in all versions up to, and including, 6.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is only exploitable on sites with addslashes disabled.

PLUGIN Modern Events Calendar Lite

CVE-2021-4458

MEDIUM CVSS 5.9 2025-07-12
Threat Entry Updated 2025-07-15

CVE-2025-7518 - WordPress Core

The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via the get_local_filename() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CORE WordPress Core

CVE-2025-7518

MEDIUM CVSS 4.9 2025-07-12
Scroll to top