Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 3301-3320 of 15036 records
Threat Entry Updated 2025-11-06

CVE-2025-11271 - Easy Digital Downloads Plugin

The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification bypass. The verification is unconditionally skipped when the POST body includes verification_override=1. Because this value is attacker-supplied, an unauthenticated actor can submit a forged IPN and have it treated as verified, even on production sites and with verification otherwise enabled. A valid PayPal transaction id is needed, restricting order manipulation to orders placed by the attacker. This, in turn, requires them to have a customer…

PLUGIN Easy Digital Downloads

CVE-2025-11271

MEDIUM CVSS 5.3 2025-11-06
Threat Entry Updated 2025-11-06

CVE-2025-10691 - Easy Email Subscription Plugin

The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the show_editsub_page() function. This makes it possible for unauthenticated attackers to delete arbitrary subscribers via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Easy Email Subscription

CVE-2025-10691

MEDIUM CVSS 4.3 2025-11-06
Threat Entry Updated 2025-11-06

CVE-2025-10683 - Easy Email Subscription Plugin

The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions up to, and including, 1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Easy Email Subscription

CVE-2025-10683

MEDIUM CVSS 4.9 2025-11-06
Threat Entry Updated 2025-11-06

CVE-2025-12497 - Premium Portfolio Features For Phlox Theme Plugin

The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3.10 via the 'args[extra_template_path]' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

PLUGIN Premium Portfolio Features For Phlox Theme

CVE-2025-12497

HIGH CVSS 8.1 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-11745 - Ad Inserter Plugin

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field through the plugin's 'adinserter' shortcode in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ad Inserter

CVE-2025-11745

MEDIUM CVSS 6.4 2025-11-05
Threat Entry Updated 2025-12-04

CVE-2025-12468 - Funnelkit Automations Plugin

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.4.1 via the '/wc-coupons/' REST API endpoint. This is due to the endpoint being marked as a public API (`public_api = true`), which results in the endpoint being registered with `permission_callback => '__return_true'`, bypassing all authentication and capability checks. This makes it possible for unauthenticated attackers to extract sensitive data including all WooCommerce coupon codes, coupon IDs, and expiration status.

PLUGIN Funnelkit Automations

CVE-2025-12468

MEDIUM CVSS 5.3 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-12192 - Events Calendar Plugin

The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system report whenever "Yes, automatically share my system information with The Events Calendar support team" setting is enabled.

PLUGIN Events Calendar

CVE-2025-12192

MEDIUM CVSS 5.3 2025-11-05
Threat Entry Updated 2025-12-04

CVE-2025-12469 - Funnelkit Automations Plugin

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.4.1. This is due to the plugin not properly verifying that a user is authorized to perform administrative actions in the `bwfan_test_email` AJAX handler. The nonce used for verification is publicly exposed to all visitors (including unauthenticated users) via the frontend JavaScript localization, and the `check_nonce()` function accepts low-privilege authenticated users who possess this nonce. This makes it possible for authenticated attackers,…

PLUGIN Funnelkit Automations

CVE-2025-12469

MEDIUM CVSS 4.3 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-11987 - Visual Link Preview Plugin

The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-preview shortcode in versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Visual Link Preview

CVE-2025-11987

MEDIUM CVSS 6.4 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-11820 - Graphina Elementor Charts And Graphs Plugin

The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple chart widgets in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping on data attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability affects multiple chart widgets including Area Chart, Line Chart, Column Chart, Donut Chart, Heatmap Chart, Radar Chart, Polar Chart, Pie…

PLUGIN Graphina Elementor Charts And Graphs

CVE-2025-11820

MEDIUM CVSS 6.4 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-12674 - Kiotvietsync Plugin

The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the create_media() function in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Kiotvietsync

CVE-2025-12674

CRITICAL CVSS 9.8 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-12677 - Kiotvietsync Plugin

The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the register_api_route() function in kiotvietsync/includes/public_actions/WebHookAction.php. This makes it possible for unauthenticated attackers to extract the webhook token value when configured.

PLUGIN Kiotvietsync

CVE-2025-12677

MEDIUM CVSS 5.3 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-12676 - Kiotvietsync Plugin

The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5. This is due to the plugin using a hardcoded password for authentication in the QueryControllerAdmin::authenticated function. This makes it possible for unauthenticated attackers to create and sync products.

PLUGIN Kiotvietsync

CVE-2025-12676

MEDIUM CVSS 5.3 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-12675 - Kiotvietsync Plugin

The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveConfig() function in all versions up to, and including, 1.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's config.

PLUGIN Kiotvietsync

CVE-2025-12675

MEDIUM CVSS 4.3 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-12384 - And Other Files Plugin

The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action in the "bplde_save_document_library", "bplde_get_all", "bplde_get_single", and "bplde_delete_document_library" functions. This makes it possible for unauthenticated attackers to create, read, update, and delete arbitrary document_library posts.

PLUGIN And Other Files

CVE-2025-12384

HIGH CVSS 8.6 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-12139 - Integrate Google Drive Plugin

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including Google OAuth credentials (client_id and client_secret) and Google account email addresses.

PLUGIN Integrate Google Drive

CVE-2025-12139

HIGH CVSS 7.5 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-12388 - Responsive Image And Content Carousel Plugin

The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.1.5. This is due to the plugin not validating user-supplied URLs before passing them to the wp_remote_request() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Responsive Image And Content Carousel

CVE-2025-12388

MEDIUM CVSS 6.4 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-11917 - Wpematico Rss Feed Fetcher Plugin

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.11 via the wpematico_test_feed() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Wpematico Rss Feed Fetcher

CVE-2025-11917

MEDIUM CVSS 6.4 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-11373 - Post Slider Carousel Plugin

The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability checks in the "depicter-media-upload" AJAX route in all versions up to, and including, 4.0.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload limited files on the affected site's server.

PLUGIN Post Slider Carousel

CVE-2025-11373

MEDIUM CVSS 4.3 2025-11-05
Threat Entry Updated 2025-11-06

CVE-2025-6027 - Ace User Management Plugin

The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associated with the user who requested it, allowing any authenticated users, such as subscriber to reset the password of arbitrary accounts, including administrators.

PLUGIN Ace User Management

CVE-2025-6027

MEDIUM CVSS 6.3 2025-11-05
Scroll to top