Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 3141-3160 of 10866 records
Threat Entry Updated 2025-06-16

CVE-2025-6064 - Wp Url Shortener Plugin

The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the 'url_shortener_settings' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Url Shortener

CVE-2025-6064

MEDIUM CVSS 6.1 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6063 - Xisearch Bar Plugin

The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing or incorrect nonce validation on the 'xisearch-key-config' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Xisearch Bar

CVE-2025-6063

MEDIUM CVSS 6.1 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6055 - Zen Social Sticky Plugin

The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing or incorrect nonce validation on the 'zen-social-sticky/zen-sticky-social.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Zen Social Sticky

CVE-2025-6055

MEDIUM CVSS 6.1 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6062 - Yougler Blogger Profile Page Plugin

The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due to missing or incorrect nonce validation on the 'yougler-plugin.php' page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Yougler Blogger Profile Page

CVE-2025-6062

MEDIUM CVSS 4.3 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-5589 - Streamweasels Kick Integration Plugin

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Streamweasels Kick Integration

CVE-2025-5589

MEDIUM CVSS 6.4 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-5336 - Click To Chat Plugin

The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter in all versions up to, and including, 4.22 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Click To Chat

CVE-2025-5336

MEDIUM CVSS 6.4 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-4216 - Ecava Diot Scada Plugin

The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and including, 1.0.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ecava Diot Scada

CVE-2025-4216

MEDIUM CVSS 6.4 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6040 - Easy Flashcards Plugin

The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing or incorrect nonce validation on the 'ef_settings_submenu' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Easy Flashcards

CVE-2025-6040

MEDIUM CVSS 6.1 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-4592 - Ai Image Generator Lab Plugin

The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the 'wpz-ai-images' page. This makes it possible for unauthenticated attackers to update the plugin's API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ai Image Generator Lab

CVE-2025-4592

MEDIUM CVSS 4.3 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-4187 - Plugin For Wordpress Is Vulnerable To Directory Traversal In All Versions Up To

The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 via the userpro_fbconnect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Plugin For Wordpress Is Vulnerable To Directory Traversal In All Versions Up To

CVE-2025-4187

MEDIUM CVSS 5.9 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6059 - Seraphinite Accelerator Plugin

The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing or incorrect nonce validation on the 'OnAdminApi_CacheOpBegin' function. This makes it possible for unauthenticated attackers to perform several administrative actions, including deleting the cache, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Seraphinite Accelerator

CVE-2025-6059

MEDIUM CVSS 4.3 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6012 - Auto Attachments Plugin

The Auto Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Auto Attachments

CVE-2025-6012

MEDIUM CVSS 5.5 2025-06-13
Threat Entry Updated 2025-06-16

CVE-2025-5923 - Game Review Block Plugin

The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Game Review Block

CVE-2025-5923

MEDIUM CVSS 6.4 2025-06-13
Threat Entry Updated 2025-06-16

CVE-2025-5815 - Traffic Monitor Plugin

The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_bot_flags() function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to disabled bot logging.

PLUGIN Traffic Monitor

CVE-2025-5815

MEDIUM CVSS 5.3 2025-06-13
Threat Entry Updated 2025-07-10

CVE-2025-5950 - Indieblocks Plugin

The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all versions up to, and including, 0.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Indieblocks

CVE-2025-5950

MEDIUM CVSS 6.4 2025-06-13
Threat Entry Updated 2025-07-10

CVE-2025-5938 - Digital Marketing And Agency Templates Addons For Elementor Plugin

The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the import_templates() function. This makes it possible for unauthenticated attackers to trigger an import via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Digital Marketing And Agency Templates Addons For Elementor

CVE-2025-5938

MEDIUM CVSS 5.3 2025-06-13
Threat Entry Updated 2025-06-16

CVE-2025-5939 - Telegram For Wp Plugin

The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Telegram For Wp

CVE-2025-5939

MEDIUM CVSS 4.4 2025-06-13
Threat Entry Updated 2025-06-16

CVE-2025-5841 - Acf Onyx Poll Plugin

The ACF Onyx Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Acf Onyx Poll

CVE-2025-5841

MEDIUM CVSS 6.4 2025-06-13
Threat Entry Updated 2025-06-16

CVE-2025-5233 - Color Palette Plugin

The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hex’ parameter in all versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Color Palette

CVE-2025-5233

MEDIUM CVSS 6.4 2025-06-13
Threat Entry Updated 2025-06-16

CVE-2025-5926 - Link Shield Plugin

The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.4. This is due to missing or incorrect nonce validation on the link_shield_menu_options() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Link Shield

CVE-2025-5926

MEDIUM CVSS 6.1 2025-06-13
Scroll to top