Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 3201-3220 of 10866 records
Threat Entry Updated 2025-06-06

CVE-2025-5019 - Hive Support Plugin

The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the hs_update_ai_chat_settings() function. This makes it possible for unauthenticated attackers to reconfigure the plugin’s AI/chat settings (including API keys) and to potentially redirect notifications or leak data to attacker-controlled endpoints via a forged request granted they can trick a site administrator into performing an action such as…

PLUGIN Hive Support

CVE-2025-5019

MEDIUM CVSS 5.4 2025-06-06
Threat Entry Updated 2025-07-10

CVE-2025-4966 - Wp Online Users Stats Plugin

The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation within the hk_dataset_results() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Online Users Stats

CVE-2025-4966

MEDIUM CVSS 6.1 2025-06-06
Threat Entry Updated 2025-07-10

CVE-2025-4964 - Wp Online Users Stats Plugin

The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Online Users Stats

CVE-2025-4964

MEDIUM CVSS 4.9 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-2935 - Stop Spammer Registrations Plugin

The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.7. This is due to missing or incorrect nonce validation in the 'ss_option_maint.php' and 'ss_user_filter_list' files. This makes it possible for unauthenticated attackers to delete pending comments, and re-enable a previously blocked user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Stop Spammer Registrations

CVE-2025-2935

MEDIUM CVSS 5.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-1777 - Bm Content Builder Plugin

The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'ux_cb_page_options_save' function in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bm Content Builder

CVE-2025-1777

MEDIUM CVSS 6.4 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-1778 - Art Theme

The Art Theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'arttheme_theme_option_restore' AJAX function in all versions up to, and including, 3.12.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete the theme option.

THEME Art

CVE-2025-1778

MEDIUM CVSS 4.3 2025-06-06
Threat Entry Updated 2025-06-06

CVE-2025-5733 - Modern Events Calendar Lite Plugin

The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Modern Events Calendar Lite

CVE-2025-5733

MEDIUM CVSS 5.3 2025-06-06
Threat Entry Updated 2025-07-10

CVE-2025-5341 - Forminator Forms Plugin

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id' and 'data-size’ parameters in all versions up to, and including, 1.44.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Forminator Forms

CVE-2025-5341

MEDIUM CVSS 6.4 2025-06-05
Threat Entry Updated 2025-06-04

CVE-2025-4580 - File Provider Plugin

The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN File Provider

CVE-2025-4580

MEDIUM CVSS 4.3 2025-06-04
Threat Entry Updated 2025-07-10

CVE-2025-5539 - Wp Easy Contact Plugin

The Simple Contact Form Plugin for WordPress – WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Easy Contact

CVE-2025-5539

MEDIUM CVSS 6.4 2025-06-04
Threat Entry Updated 2025-06-04

CVE-2025-5532 - Student Directory Plugin

The Campus Directory – Faculty, Staff & Student Directory Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Student Directory

CVE-2025-5532

MEDIUM CVSS 6.4 2025-06-04
Threat Entry Updated 2025-06-04

CVE-2025-5531 - Team Directory Plugin

The Employee Directory – Staff Listing & Team Directory Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Team Directory

CVE-2025-5531

MEDIUM CVSS 6.4 2025-06-04
Threat Entry Updated 2025-06-04

CVE-2025-5340 - Music Player For Elementor Plugin

The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘album_buy_url’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Music Player For Elementor

CVE-2025-5340

MEDIUM CVSS 6.4 2025-06-03
Threat Entry Updated 2025-06-04

CVE-2025-4671 - Profile Builder Plugin

The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Profile Builder

CVE-2025-4671

MEDIUM CVSS 6.4 2025-06-03
Threat Entry Updated 2025-06-04

CVE-2025-4205 - Popup Maker Plugin

The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all versions up to, and including, 1.20.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Popup Maker

CVE-2025-4205

MEDIUM CVSS 6.4 2025-06-03
Threat Entry Updated 2025-06-04

CVE-2025-5116 - Wp Plugin Info Card

The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ parameter in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This issue is due to an incomplete patch for CVE-2025-31835.

PLUGIN Wp Plugin Info Card

CVE-2025-5116

MEDIUM CVSS 6.4 2025-06-03
Threat Entry Updated 2025-06-04

CVE-2025-4420 - Vayu Blocks Plugin

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerWidth’ parameter in all versions up to, and including, 1.3.1 due to a missing capability check on the vayu_blocks_option_panel_callback() function and insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Vayu Blocks

CVE-2025-4420

MEDIUM CVSS 6.4 2025-06-03
Threat Entry Updated 2025-06-04

CVE-2025-1725 - File Manager Plugin

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN File Manager

CVE-2025-1725

MEDIUM CVSS 6.4 2025-06-03
Threat Entry Updated 2025-07-10

CVE-2025-5103 - Ultimate Gift Cards For Woocommerce Plugin

The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the 'default_price' and 'product_id' parameters in all versions up to, and including, 3.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ultimate Gift Cards For Woocommerce

CVE-2025-5103

MEDIUM CVSS 4.9 2025-06-03
Threat Entry Updated 2025-06-05

CVE-2025-3662 - Fancybox For Plugin

The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+ Stored XSS, however one of our researcher (Marc Montpas) escalated it to an Unauthenticated Stored XSS

PLUGIN Fancybox For

CVE-2025-3662

MEDIUM CVSS 6.1 2025-06-03
Scroll to top