Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,857
Critical0
High0
Medium10,857
Reset
Showing 1401-1420 of 10857 records
Threat Entry Updated 2026-01-13

CVE-2025-13900 - Wp Popup Magic Plugin

The WP Popup Magic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the [wppum_end] shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Popup Magic

CVE-2025-13900

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13853 - Nearby Now Reviews Plugin

The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter of the nn-tech shortcode in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Nearby Now Reviews

CVE-2025-13853

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13729 - Entry Views Plugin

The Entry Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'entry-views' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Entry Views

CVE-2025-13729

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13895 - Top Position Google Finance Plugin

The Top Position Google Finance plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 0.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Top Position Google Finance

CVE-2025-13895

MEDIUM CVSS 6.1 2026-01-09
Threat Entry Updated 2026-04-15

CVE-2026-0627 - AMP for WP – Accelerated Mobile Pages Plugin

The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.1.10. This is due to insufficient sanitization of SVG file content that only removes `` tags while allowing other XSS vectors such as event handlers (onload, onerror, onmouseover), foreignObject elements, and SVG animation attributes. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts via malicious SVG file uploads that will execute whenever a user views the uploaded file.

PLUGIN AMP for WP – Accelerated Mobile Pages

CVE-2026-0627

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14146 - Booking Calendar Plugin

The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPBC_FLEXTIMELINE_NAV` AJAX action. This is due to the nonce verification being conditionally disabled by default (`booking_is_nonce_at_front_end` option is `'Off'` by default). When the `booking_is_show_popover_in_timeline_front_end` option is enabled (which is the default in demo installations and can be enabled by administrators), it is possible for unauthenticated attackers to extract sensitive booking data including customer names, email addresses, phone numbers, and booking details.

PLUGIN Booking Calendar

CVE-2025-14146

MEDIUM CVSS 5.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13935 - Elearning And Online Course Solution Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completion in all versions up to, and including, 3.9.2. This is due to missing enrollment verification in the 'mark_course_complete' function. This makes it possible for authenticated attackers, with subscriber level access and above, to mark any course as completed.

PLUGIN Elearning And Online Course Solution

CVE-2025-13935

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13934 - Elearning And Online Course Solution Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollment in all versions up to, and including, 3.9.3. This is due to a missing capability check and purchasability validation in the `course_enrollment()` AJAX handler. This makes it possible for authenticated attackers, with subscriber level access and above, to enroll themselves in any course without going through the proper purchase flow.

PLUGIN Elearning And Online Course Solution

CVE-2025-13934

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13753 - Drop Table Builder Plugin

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect authorization check on the save_table() function in all versions up to, and including, 2.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new wptb-table posts.

PLUGIN Drop Table Builder

CVE-2025-13753

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-13628 - Elearning And Online Course Solution Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability check on the 'bulk_action_handler' and 'coupon_permanent_delete' functions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with subscriber level access and above, to delete, activate, deactivate, or trash arbitrary coupons.

PLUGIN Elearning And Online Course Solution

CVE-2025-13628

MEDIUM CVSS 4.3 2026-01-09
Threat Entry Updated 2026-04-15

CVE-2026-0563 - WP Google Street View (with 360° virtual tour) & Google maps + Local SEO Plugin

The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpgsv_map' shortcode in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN WP Google Street View (with 360° virtual tour) & Google maps + Local SEO

CVE-2026-0563

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-15019 - Woocommerce Plugin

The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bialty_cs_alt' post meta in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the post editor.

PLUGIN Woocommerce

CVE-2025-15019

MEDIUM CVSS 6.4 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14980 - Betterdocs Plugin

The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in plugin settings.

PLUGIN Betterdocs

CVE-2025-14980

MEDIUM CVSS 6.5 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14893 - Indieweb Plugin

The IndieWeb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Telephone' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Indieweb

CVE-2025-14893

MEDIUM CVSS 6.4 2026-01-09
Scroll to top