Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 2941-2960 of 15036 records
Threat Entry Updated 2025-12-02

CVE-2025-13685 - Gallery Photo Gallery Plugin

The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due to missing nonce verification on the bulk action functionality in the 'process_bulk_action()' function. This makes it possible for unauthenticated attackers to perform bulk operations (delete, publish, or unpublish galleries) via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

PLUGIN Gallery Photo Gallery

CVE-2025-13685

MEDIUM CVSS 4.3 2025-12-02
Threat Entry Updated 2025-12-02

CVE-2025-13140 - Drop Wordpress Form Builder Plugin

The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12.20. This is due to missing nonce validation on the SurveyJS_DeleteSurvey AJAX action. This makes it possible for unauthenticated attackers to delete surveys via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Drop Wordpress Form Builder

CVE-2025-13140

MEDIUM CVSS 4.3 2025-12-02
Threat Entry Updated 2025-12-02

CVE-2025-12483 - Tables And Charts Manager For Wordpress Plugin

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'query' parameter in all versions up to, and including, 3.11.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Version 3.11.13 raises the minimum user-level for exploitation to administrator. 3.11.14…

PLUGIN Tables And Charts Manager For Wordpress

CVE-2025-12483

MEDIUM CVSS 6.5 2025-12-02
Threat Entry Updated 2026-01-30

CVE-2025-13000 - Db Access Plugin

The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacks

PLUGIN Db Access

CVE-2025-13000

HIGH CVSS 7.7 2025-12-02
Threat Entry Updated 2026-01-30

CVE-2025-13001 - Donations Plugin

The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users, such as admin to perform SQL injection attacks

PLUGIN Donations

CVE-2025-13001

MEDIUM CVSS 4.1 2025-12-02
Threat Entry Updated 2025-12-02

CVE-2025-13606 - Users Plugin

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.19. This is due to missing or incorrect nonce validation on the `parseData` function. This makes it possible for unauthenticated attackers to export sensitive information including user data, email addresses, password hashes, and WooCommerce data to an attacker-controlled file path on the server via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Users

CVE-2025-13606

MEDIUM CVSS 6.5 2025-12-02
Threat Entry Updated 2025-12-02

CVE-2025-13387 - Kadence Woocommerce Email Designer Plugin

The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Kadence Woocommerce Email Designer

CVE-2025-13387

HIGH CVSS 7.2 2025-12-02
Threat Entry Updated 2025-12-02

CVE-2025-12529 - Cost Calculator Builder Plugin

The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrdersFiles() function in all versions up to, and including, 3.6.3. This makes it possible for unauthenticated attackers to inject arbitrary file paths into the orders that are removed, when an administrator deletes them. This can lead to remote code execution when the right file is deleted (such as wp-config.php). This vulnerability requires the Cost Calculator Builder Pro version to be installed along with the free version in order to…

PLUGIN Cost Calculator Builder

CVE-2025-12529

HIGH CVSS 8.8 2025-12-02
Threat Entry Updated 2025-12-02

CVE-2025-13697 - Template Library Plugin

The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘timestamp’ attribute in all versions up to, and including, 2.2.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Template Library

CVE-2025-13697

MEDIUM CVSS 6.4 2025-12-02
Threat Entry Updated 2025-12-01

CVE-2025-13615 - Streamtube Core Plugin

The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if the 'registration password fields' enabled in theme options.

PLUGIN Streamtube Core

CVE-2025-13615

CRITICAL CVSS 9.8 2025-11-30
Threat Entry Updated 2025-12-01

CVE-2025-13737 - Nextend Facebook Connect Plugin

The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is due to missing or incorrect nonce validation on the 'unlinkUser' function. This makes it possible for unauthenticated attackers to unlink the user's social login via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Nextend Facebook Connect

CVE-2025-13737

MEDIUM CVSS 4.3 2025-11-28
Threat Entry Updated 2025-12-01

CVE-2025-13692 - Unlimited Elements For Elementor Plugin

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. A form with a file upload field must be created with the premium version of the plugin in order to exploit the vulnerability. However, once the form exists, the vulnerability is exploitable…

PLUGIN Unlimited Elements For Elementor

CVE-2025-13692

HIGH CVSS 7.2 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12971 - File Manager Plugin

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'wcp_change_post_folder' function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to move arbitrary folder contents to arbitrary folders.

PLUGIN File Manager

CVE-2025-12971

MEDIUM CVSS 4.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-10476 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate several database fix actions. This only affects sites with premium activated.

PLUGIN Wp Fastest Cache

CVE-2025-10476

MEDIUM CVSS 4.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13381 - Ays Chatgpt Assistant Plugin

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files.

PLUGIN Ays Chatgpt Assistant

CVE-2025-13381

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13378 - Ays Chatgpt Assistant Plugin

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.0 via the ays_chatgpt_pinecone_upsert function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Ays Chatgpt Assistant

CVE-2025-13378

MEDIUM CVSS 6.5 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12584 - Quick View For Woocommerce Plugin

The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX endpoint due to insufficient restrictions on which products can be included. This makes it possible for unauthenticated attackers to extract data from private products that they should not have access to.

PLUGIN Quick View For Woocommerce

CVE-2025-12584

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13536 - Blubrry Powerpress Plugin

The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting execution when validation fails in the 'powerpress_edit_post' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Blubrry Powerpress

CVE-2025-13536

HIGH CVSS 8.8 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13441 - Hide Category By User Role For Woocommerce Plugin

The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This is due to a missing capability check on the admin_init hook that executes wp_cache_flush(). This makes it possible for unauthenticated attackers to flush the site's object cache via forged requests, potentially degrading site performance.

PLUGIN Hide Category By User Role For Woocommerce

CVE-2025-13441

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13157 - Qode Wishlist For Woocommerce Plugin

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the 'qode_wishlist_for_woocommerce_wishlist_table_item_callback' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to update the public view of arbitrary wishlists.

PLUGIN Qode Wishlist For Woocommerce

CVE-2025-13157

MEDIUM CVSS 5.3 2025-11-27
Scroll to top