Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 2961-2980 of 15036 records
Threat Entry Updated 2025-12-01

CVE-2025-13525 - Wp Directory Kit Plugin

The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Directory Kit

CVE-2025-13525

MEDIUM CVSS 6.1 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12185 - Stafflist Plugin

The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Stafflist

CVE-2025-12185

MEDIUM CVSS 4.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13143 - Social Polls By Opinionstage Plugin

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.12.0. This is due to missing or insufficient nonce validation on the disconnect_account_action function. This makes it possible for unauthenticated attackers to disconnect the site from the Opinion Stage platform integration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Social Polls By Opinionstage

CVE-2025-13143

MEDIUM CVSS 4.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12123 - Customer Reviews Collector For Woocommerce Plugin

The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email-text' parameter in all versions up to, and including, 4.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Customer Reviews Collector For Woocommerce

CVE-2025-12123

MEDIUM CVSS 6.1 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-7820 - Skt Paypal For Woocommerce Plugin

The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 1.4. This is due to the plugin only enforcing client side controls instead of server-side controls when processing payments. This makes it possible for unauthenticated attackers to make confirmed purchases without actually paying for them.

PLUGIN Skt Paypal For Woocommerce

CVE-2025-7820

HIGH CVSS 7.5 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13675 - Tiger Theme

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.php' file not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

THEME Tiger

CVE-2025-13675

CRITICAL CVSS 9.8 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13680 - Tiger Theme

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the plugin allowing a user to update the user role through the $user->set_role() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

THEME Tiger

CVE-2025-13680

HIGH CVSS 8.8 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13540 - Tiare Membership Plugin

The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the 'tiare_membership_init_rest_api_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

PLUGIN Tiare Membership

CVE-2025-13540

CRITICAL CVSS 9.8 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13539 - Findall Membership Plugin

The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.4. This is due to the plugin not properly logging in a user with the data that was previously verified through the 'findall_membership_check_facebook_user' and the 'findall_membership_check_google_user' functions. This makes it possible for unauthenticated attackers to log in as administrative users, as long as they have an existing account on the site which can easily be created by default through the temp user functionality, and access to the administrative user's email.

PLUGIN Findall Membership

CVE-2025-13539

CRITICAL CVSS 9.8 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13538 - Findall Listing Plugin

The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the 'findall_listing_user_registration_additional_params' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site. Note: The vulnerability can only be exploited if the FindAll Membership plugin is also activated, because user registration is in that plugin.

PLUGIN Findall Listing

CVE-2025-13538

CRITICAL CVSS 9.8 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12151 - Simple Folio Plugin

The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Folio

CVE-2025-12151

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12713 - Soundslides Plugin

The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Soundslides

CVE-2025-12713

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12712 - Shouty Plugin

The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up to, and including, 0.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shouty

CVE-2025-12712

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12670 - Wp Twitpic Plugin

The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Twitpic

CVE-2025-12670

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12666 - Google Drive Upload And Download Link Plugin

The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter of the 'atachfilegoogle' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Google Drive Upload And Download Link

CVE-2025-12666

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12649 - Sorttable Post Plugin

The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sorttablepost shortcode in all versions up to, and including, 4.2. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via mouse interaction.

PLUGIN Sorttable Post

CVE-2025-12649

MEDIUM CVSS 6.4 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12579 - Reuters Direct Plugin

The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'logoff' action in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to reset the plugin's settings.

PLUGIN Reuters Direct

CVE-2025-12579

MEDIUM CVSS 5.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-12578 - Reuters Direct Plugin

The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the the 'class-reuters-direct-settings.php' page. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Reuters Direct

CVE-2025-12578

MEDIUM CVSS 4.3 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-9191 - Houzez Theme

The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in saved-search-item.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target…

THEME Houzez

CVE-2025-9191

MEDIUM CVSS 6.3 2025-11-26
Threat Entry Updated 2025-12-01

CVE-2025-9163 - Houzez Theme

The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping in the houzez_property_img_upload() and houzez_property_attachment_upload() functions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

THEME Houzez

CVE-2025-9163

MEDIUM CVSS 6.1 2025-11-26
Scroll to top