Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 3181-3200 of 15036 records
Threat Entry Updated 2025-11-12

CVE-2025-11454 - Customize The Mobile Version Without Redirections Plugin

The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable to SQL Injection via the eos_scfm_duplicate_post_as_draft() function in all versions up to, and including, 0.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with COntributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Customize The Mobile Version Without Redirections

CVE-2025-11454

MEDIUM CVSS 6.5 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12903 - Woo Payment Gateway Plugin

The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wc-braintree/v1/3ds/vaulted_nonce REST API endpoint in all versions up to, and including, 3.2.78. This is due to the endpoint being registered with permission_callback set to __return_true and processing user-supplied token IDs without verifying ownership or authentication. This makes it possible for unauthenticated attackers to retrieve payment method nonces for any stored payment token in the system, which can be used to create fraudulent transactions, charge customer credit cards, or…

PLUGIN Woo Payment Gateway

CVE-2025-12903

HIGH CVSS 7.5 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12732 - Ultimate Csv Xml Importer For Wordpress Plugin

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attackers, with Author-level access or higher, to extract sensitive information including OpenAI API keys configured through the plugin's admin interface.

PLUGIN Ultimate Csv Xml Importer For Wordpress

CVE-2025-12732

MEDIUM CVSS 4.3 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12633 - Bookit Plugin

The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API Endpoint in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to connect their Stripe account and receive payments.

PLUGIN Bookit

CVE-2025-12633

HIGH CVSS 7.5 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12018 - Memberfindme Plugin

The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Memberfindme

CVE-2025-12018

MEDIUM CVSS 4.4 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12113 - Bulk Update Alt Texts For Images Plugin

The Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the atgai_delete_api_key() function in all versions up to, and including, 1.8.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the API key connected to the site.

PLUGIN Bulk Update Alt Texts For Images

CVE-2025-12113

MEDIUM CVSS 4.3 2025-11-12
Threat Entry Updated 2025-12-19

CVE-2025-11560 - Team Members Showcase Plugin

The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it back in the page, leading to reflected cross-site scripting, which could be used against high-privilege users such as admins.

PLUGIN Team Members Showcase

CVE-2025-11560

HIGH CVSS 7.1 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12901 - Asgaros Forum Plugin

The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to missing nonce validation on the set_subscription_level() function. This makes it possible for unauthenticated attackers to modify the subscription settings of authenticated users via a forged request granted they can trick a logged-in user into performing an action such as clicking on a link.

PLUGIN Asgaros Forum

CVE-2025-12901

MEDIUM CVSS 4.3 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12833 - Geodirectory Plugin

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to attach arbitrary image files to arbitrary places.

PLUGIN Geodirectory

CVE-2025-12833

MEDIUM CVSS 4.3 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12087 - Wishlist And Save For Later For Woocommerce Plugin

The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.22 via the 'awwlm_remove_added_wishlist_page' AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete wishlist items from other user's wishlists.

PLUGIN Wishlist And Save For Later For Woocommerce

CVE-2025-12087

MEDIUM CVSS 4.3 2025-11-12
Threat Entry Updated 2025-11-12

CVE-2025-12846 - Blocksy Companion Plugin

The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to insufficient file type validation detecting SVG files, allowing double extension files to bypass sanitization while being accepted as a valid SVG file. This makes it possible for authenticated attackers, with author level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Blocksy Companion

CVE-2025-12846

HIGH CVSS 8.8 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12953 - Business Directory Plugin

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "rtcl_ajax_add_listing_type", "rtcl_ajax_update_listing_type", and "rtcl_ajax_delete_listing_type" function in all versions up to, and including, 5.2.0. This makes it possible for authenticated attackers, with subscriber level access and above, to add, update, or delete listing types.

PLUGIN Business Directory

CVE-2025-12953

MEDIUM CVSS 4.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12788 - Booking Calendar Plugin

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment verification to unauthenticated payment bypass in all versions up to, and including, 1.1.27. This is due to the plugin accepting client-controlled payment confirmation data in the tfhb_meeting_paypal_payment_confirmation_callback function without server-side verification with PayPal's API. This makes it possible for unauthenticated attackers to bypass payment requirements and confirm bookings as paid without any actual payment transaction occurring.

PLUGIN Booking Calendar

CVE-2025-12788

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12787 - Booking Calendar Plugin

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's "tfhb_meeting_form_submit_callback" function using insufficiently random values to generate booking cancellation tokens, combined with a globally shared nonce. This makes it possible for unauthenticated attackers to cancel arbitrary bookings via brute force attacks against the tfhb_meeting_form_cencel AJAX endpoint.

PLUGIN Booking Calendar

CVE-2025-12787

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12539 - Web Performance Plugin

The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing cPanel API credentials (hostname, username, and API key) in files within the web-accessible wp-content directory without adequate protection in the "Tnc_Wp_Toolbox_Settings::save_settings" function. This makes it possible for unauthenticated attackers to retrieve these credentials and use them to interact with the cPanel API, which can lead to arbitrary file uploads, remote code execution, and full compromise of the hosting environment.

PLUGIN Web Performance

CVE-2025-12539

CRITICAL CVSS 10.0 2025-11-11
Threat Entry Updated 2025-11-13

CVE-2025-11855 - Age Restriction Plugin

The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin user with a hardcoded username and arbitrary password.

PLUGIN Age Restriction

CVE-2025-11855

HIGH CVSS 7.5 2025-11-11
Threat Entry Updated 2025-11-13

CVE-2025-11307 - Before 9 Plugin

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.

PLUGIN Before 9

CVE-2025-11307

HIGH CVSS 8.8 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11237 - Make Email Customizer For Woocommerce Plugin

The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options.

PLUGIN Make Email Customizer For Woocommerce

CVE-2025-11237

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12813 - Holiday Class Post Calendar Plugin

The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'contents' parameter. This is due to a lack of sanitization of user-supplied data when creating a cache file. This makes it possible for unauthenticated attackers to execute code on the server.

PLUGIN Holiday Class Post Calendar

CVE-2025-12813

CRITICAL CVSS 9.8 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12754 - Geopost Plugin

The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost' shortcode in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Geopost

CVE-2025-12754

MEDIUM CVSS 6.4 2025-11-11
Scroll to top