Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 3561-3580 of 10866 records
Threat Entry Updated 2025-05-06

CVE-2025-3915 - Aeropage Sync For Airtable Plugin

The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'aeropageDeletePost' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts.

PLUGIN Aeropage Sync For Airtable

CVE-2025-3915

MEDIUM CVSS 4.3 2025-04-26
Threat Entry Updated 2025-05-06

CVE-2025-1458 - Element Pack Plugin

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like Dual Button, Creative Button, Image Stack and more in all versions up to, and including, 5.10.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2025-1458

MEDIUM CVSS 6.4 2025-04-26
Threat Entry Updated 2025-04-29

CVE-2025-3912 - Drop Contact Form Builder For Wordpress Plugin

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_config' function in all versions up to, and including, 1.10.35. This makes it possible for unauthenticated attackers to read the value of the plugin's settings, including API keys for integrated services.

PLUGIN Drop Contact Form Builder For Wordpress

CVE-2025-3912

MEDIUM CVSS 5.3 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3870 - 1 Decembrie 1918 Plugin

The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.dec.2012. This is due to missing or incorrect nonce validation on the 1-decembrie-1918/1-decembrie-1918.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN 1 Decembrie 1918

CVE-2025-3870

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3868 - Admin Bookmarks Plugin

The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Admin Bookmarks

CVE-2025-3868

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3867 - Ajax Comment Form Cst Plugin

The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation via the 'acform_cst_settings' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ajax Comment Form Cst

CVE-2025-3867

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3866 - Add Google Plus One Social Share Button Plugin

The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the google-plus-one-share-button page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Add Google Plus One Social Share Button

CVE-2025-3866

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3743 - Upsell Funnel Builder For Woocommerce Plugin

The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the 'add_offer_in_cart' function. This makes it possible for unauthenticated attackers to arbitrarily update the product associated with any order bump, and arbitrarily update the discount applied to any order bump item, when adding it to the cart.

PLUGIN Upsell Funnel Builder For Woocommerce

CVE-2025-3743

MEDIUM CVSS 5.3 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3923 - Prevent Direct Access Plugin

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'generate_unique_string' due to insufficient randomness of the generated file name. This makes it possible for unauthenticated attackers to extract sensitive data including files protected by the plugin if the attacker can determine the file name.

PLUGIN Prevent Direct Access

CVE-2025-3923

MEDIUM CVSS 5.3 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3861 - Prevent Direct Access Plugin

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability check on the 'pda_lite_custom_permission_check' function in versions 2.8.6 to 2.8.8.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to access and change the protection status of media.

PLUGIN Prevent Direct Access

CVE-2025-3861

MEDIUM CVSS 5.4 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-2580 - Bit Form Plugin

The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Bit Form

CVE-2025-2580

MEDIUM CVSS 4.9 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-0671 - Icegram Express Plugin

The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Icegram Express

CVE-2025-0671

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-11-26

CVE-2025-3775 - Shoplentor Plugin

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application, and can be used to query and modify information from internal services.

PLUGIN Shoplentor

CVE-2025-3775

MEDIUM CVSS 6.5 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3752 - Accessible Html5 Media Player Plugin

The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘preload’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Accessible Html5 Media Player

CVE-2025-3752

MEDIUM CVSS 6.4 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3749 - Breeze Display Plugin

The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Breeze Display

CVE-2025-3749

MEDIUM CVSS 6.4 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-46533 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdrift.no Landing pages and Domain aliases for WordPress allows Stored XSS. This issue affects Landing pages and Domain aliases for WordPress: from n/a through 0.8.

CORE WordPress Core

CVE-2025-46533

MEDIUM CVSS 5.9 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-3832 - Fusedesk Plugin

The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Fusedesk

CVE-2025-3832

MEDIUM CVSS 6.4 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-3793 - Buddy Press Force Password Change Plugin

The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with subscriber-level access and above and under certain prerequisites, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their accounts.

PLUGIN Buddy Press Force Password Change

CVE-2025-3793

MEDIUM CVSS 4.2 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-3280 - Elex Bulk Edit Products Prices Attributes For Woocommerce Basic Plugin

The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value_filter' parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Elex Bulk Edit Products Prices Attributes For Woocommerce Basic

CVE-2025-3280

MEDIUM CVSS 6.5 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-2579 - Embed Lottie Player Plugin

The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the uploaded file.

PLUGIN Embed Lottie Player

CVE-2025-2579

MEDIUM CVSS 6.4 2025-04-24
Scroll to top