Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 3241-3260 of 15036 records
Threat Entry Updated 2025-11-12

CVE-2025-11860 - Ot Twitter Feed Plugin

The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in all versions up to, and including, 1.3.1. This is due to the plugin not properly sanitizing user input and output of the 'width' and 'height' parameters. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ot Twitter Feed

CVE-2025-11860

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11859 - Paypal Donation Shortcode Plugin

The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in all versions up to, and including, 0.1. This is due to the plugin not properly sanitizing user input and output of the 'title' and 'text' parameters. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Paypal Donation Shortcode

CVE-2025-11859

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11874 - Slippy Slider Responsive Touch Navigation Slider Plugin

The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slippy-slider' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slippy Slider Responsive Touch Navigation Slider

CVE-2025-11874

MEDIUM CVSS 5.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11856 - Eventbee Ticketing Widget Plugin

The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketwidget' shortcode in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input and output of several parameters. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Eventbee Ticketing Widget

CVE-2025-11856

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11829 - Five9 Live Chat Plugin

The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the [five9-chat] shortcode in all versions up to, and including, 1.1.2. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Five9 Live Chat

CVE-2025-11829

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11828 - Bnm Blocks Plugin

The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribute in the bnm-blocks/featured-posts-1 block in all versions up to, and including, 1.2.3. This is due to insufficient input sanitization and output escaping when using user-supplied values as HTML tag names. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bnm Blocks

CVE-2025-11828

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11822 - Wp Bootstrap Tabs Plugin

The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcode in all versions up to, and including, 1.0.4. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Bootstrap Tabs

CVE-2025-11822

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11821 - Woocommerce Products By Custom Tax Plugin

The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_products_custom_tax' shortcode in all versions up to, and including, 2.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Woocommerce Products By Custom Tax

CVE-2025-11821

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11805 - Skip To Timestamp Plugin

The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in all versions up to, and including, 1.4.4. This is due to insufficient input sanitization and output escaping on the 'time' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Skip To Timestamp

CVE-2025-11805

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11457 - Easycommerce Plugin

The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in versions 0.9.0-beta2 to 1.5.0. This is due to the /easycommerce/v1/orders REST API endpoint not properly restricting the ability for users to select roles during registration. This makes it possible for unauthenticated attackers to gain administrator-level access to a vulnerable site.

PLUGIN Easycommerce

CVE-2025-11457

CRITICAL CVSS 9.8 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11170 - Cpi Wp Migration Plugin

The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Cpiwm_Import_Controller::import function in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Cpi Wp Migration

CVE-2025-11170

CRITICAL CVSS 9.8 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11168 - Mementor Core Plugin

The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5. This is due to plugin not properly handling the user switch back function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges by accessing an administrator account through the switch back functionality.

PLUGIN Mementor Core

CVE-2025-11168

HIGH CVSS 8.8 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11521 - Getastra Plugin

The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient validation of remote URLs for zip downloads and an easily guessable key in all versions up to, and including, 0.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Getastra

CVE-2025-11521

HIGH CVSS 8.1 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11451 - Amazon Auto Links Plugin

The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4.3 via the '/wp-json/wp/v2/aal_ajax_unit_loading' RST API endpoint. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Amazon Auto Links

CVE-2025-11451

HIGH CVSS 7.5 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11532 - Wisly Plugin

The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.0 due to missing validation on the 'wishlist_id' user controlled key. This makes it possible for unauthenticated attackers to remove and add items to other user's wishlists.

PLUGIN Wisly

CVE-2025-11532

MEDIUM CVSS 5.3 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-11129 - Include Fussball De Widgets Plugin

The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'type' parameters in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Include Fussball De Widgets

CVE-2025-11129

MEDIUM CVSS 6.4 2025-11-11
Threat Entry Updated 2025-11-12

CVE-2025-12399 - Alex Reservations Plugin

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST endpoint in all versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Alex Reservations

CVE-2025-12399

HIGH CVSS 7.2 2025-11-08
Threat Entry Updated 2025-11-12

CVE-2025-12092 - Cyan Backup Plugin

The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' functionality in all versions up to, and including, 2.5.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Cyan Backup

CVE-2025-12092

MEDIUM CVSS 6.5 2025-11-08
Threat Entry Updated 2025-11-12

CVE-2025-12837 - Athemes Addons For Elementor Lite Plugin

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Action widget in versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping on user-supplied values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Athemes Addons For Elementor Lite

CVE-2025-12837

MEDIUM CVSS 6.4 2025-11-08
Threat Entry Updated 2025-11-12

CVE-2025-12643 - Saphali Liqpay For Donate Plugin

The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay' shortcode in all versions up to, and including, 1.0.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Saphali Liqpay For Donate

CVE-2025-12643

MEDIUM CVSS 6.4 2025-11-08
Scroll to top