Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 3661-3680 of 10866 records
Threat Entry Updated 2025-04-08

CVE-2024-13820 - Melhor Envio Cotacao Plugin

The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.15.9 via the 'run' function, which uses a hardcoded hash. This makes it possible for unauthenticated attackers to extract sensitive data including environment information, plugin tokens, shipping configurations, and limited vendor information.

PLUGIN Melhor Envio Cotacao

CVE-2024-13820

MEDIUM CVSS 5.3 2025-04-08
Threat Entry Updated 2025-04-08

CVE-2025-2519 - Sreamit Theme

The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient file validation in the 'st_send_download_file' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to download arbitrary files.

THEME Sreamit

CVE-2025-2519

MEDIUM CVSS 6.5 2025-04-08
Threat Entry Updated 2025-04-07

CVE-2025-1264 - Broken Link Checker Seo Plugin

The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to SQL Injection via the 'orderBy' parameter in all versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Broken Link Checker Seo

CVE-2025-1264

MEDIUM CVSS 6.5 2025-04-06
Threat Entry Updated 2025-06-04

CVE-2025-0839 - Zoomsounds Plugin

The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Zoomsounds

CVE-2025-0839

MEDIUM CVSS 6.4 2025-04-05
Threat Entry Updated 2025-06-04

CVE-2025-2789 - Multivendorx Plugin

The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_table_rate_shipping_row function in all versions up to, and including, 4.2.19. This makes it possible for unauthenticated attackers to delete Table Rates that can impact the shipping cost calculations.

PLUGIN Multivendorx

CVE-2025-2789

MEDIUM CVSS 5.3 2025-04-05
Threat Entry Updated 2025-04-07

CVE-2025-1233 - Lafka Plugin

The Lafka Plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_options_upload' AJAX function in all versions up to, and including, 7.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the theme option that overrides the site.

PLUGIN Lafka

CVE-2025-1233

MEDIUM CVSS 4.3 2025-04-05
Threat Entry Updated 2025-04-07

CVE-2025-2544 - Ai Content Pipelines Plugin

The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Ai Content Pipelines

CVE-2025-2544

MEDIUM CVSS 6.4 2025-04-05
Threat Entry Updated 2025-04-07

CVE-2025-2889 - Link Library Plugin

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Link Library

CVE-2025-2889

MEDIUM CVSS 6.4 2025-04-05
Threat Entry Updated 2025-04-07

CVE-2025-32267 - WordPress Core

Cross-Site Request Forgery (CSRF) vulnerability in wpzinc Post to Social Media – WordPress to Hootsuite allows Cross Site Request Forgery. This issue affects Post to Social Media – WordPress to Hootsuite: from n/a through 1.5.8.

CORE WordPress Core

CVE-2025-32267

MEDIUM CVSS 4.3 2025-04-04
Threat Entry Updated 2025-04-07

CVE-2025-32257 - WordPress Core

Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2.

CORE WordPress Core

CVE-2025-32257

MEDIUM CVSS 5.3 2025-04-04
Threat Entry Updated 2026-02-20

CVE-2025-32238 - Online Booking Scheduling Calendar Plugin

Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita allows Retrieve Embedded Sensitive Data. This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.5.2.

PLUGIN Online Booking Scheduling Calendar

CVE-2025-32238

MEDIUM CVSS 4.3 2025-04-04
Threat Entry Updated 2025-04-07

CVE-2025-32218 - WordPress Core

Missing Authorization vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.4.

CORE WordPress Core

CVE-2025-32218

MEDIUM CVSS 5.4 2025-04-04
Threat Entry Updated 2025-04-07

CVE-2025-32172 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yuri Baranov YaMaps for WordPress allows Stored XSS. This issue affects YaMaps for WordPress: from n/a through 0.6.31.

CORE WordPress Core

CVE-2025-32172

MEDIUM CVSS 6.5 2025-04-04
Threat Entry Updated 2025-04-07

CVE-2025-32166 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in John Housholder Emma for WordPress allows Stored XSS. This issue affects Emma for WordPress: from n/a through 1.3.3.

CORE WordPress Core

CVE-2025-32166

MEDIUM CVSS 6.5 2025-04-04
Threat Entry Updated 2025-08-08

CVE-2025-2797 - Woffice Plugin

The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.4.21. This is due to missing or incorrect nonce validation on the 'woffice_handle_user_approval_actions' function. This makes it possible for unauthenticated attackers to approve registration for any user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Woffice

CVE-2025-2797

MEDIUM CVSS 5.4 2025-04-04
Threat Entry Updated 2025-04-07

CVE-2025-2836 - And User Login Plugin

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘payment_method’ parameter in all versions up to, and including, 6.0.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN And User Login

CVE-2025-2836

MEDIUM CVSS 6.4 2025-04-04
Threat Entry Updated 2025-04-29

CVE-2025-2279 - Maps Plugin

The Maps WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Maps

CVE-2025-2279

MEDIUM CVSS 5.9 2025-04-04
Threat Entry Updated 2025-04-07

CVE-2024-13898 - Announcements To The Top Or Bottom Of Your Website Plugin

The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Announcements To The Top Or Bottom Of Your Website

CVE-2024-13898

MEDIUM CVSS 4.4 2025-04-04
Threat Entry Updated 2025-05-15

CVE-2025-2299 - Luckywp Table Of Contents Plugin

The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.10. This is due to missing or incorrect nonce validation on the 'ajaxEdit' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Luckywp Table Of Contents

CVE-2025-2299

MEDIUM CVSS 6.1 2025-04-03
Scroll to top