Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 4161-4180 of 15036 records
Threat Entry Updated 2025-08-05

CVE-2025-8294 - Download Counter Plugin

The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Download Counter

CVE-2025-8294

MEDIUM CVSS 6.4 2025-08-05
Threat Entry Updated 2025-08-05

CVE-2025-8315 - Wp Easy Contact Plugin

The WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Easy Contact

CVE-2025-8315

MEDIUM CVSS 6.4 2025-08-05
Threat Entry Updated 2025-08-05

CVE-2025-8313 - Campus Directory Plugin

The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Campus Directory

CVE-2025-8313

MEDIUM CVSS 6.4 2025-08-05
Threat Entry Updated 2025-08-05

CVE-2025-7050 - Google Drive Plugin

The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in file metadata in all versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability can be exploited by the lowest authentication level permitted to upload files, including unauthenticated users, once a file upload shortcode is published on a publicly…

PLUGIN Google Drive

CVE-2025-7050

HIGH CVSS 7.2 2025-08-05
Threat Entry Updated 2025-08-04

CVE-2025-7710 - WordPress Core

The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Facebook. This makes it possible for unauthenticated attackers to log in as other users, including administrators.

CORE WordPress Core

CVE-2025-7710

CRITICAL CVSS 9.8 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-7500 - Ocean Social Sharing Plugin

The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ocean Social Sharing

CVE-2025-7500

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8488 - Header Footer Elementor Plugin

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the compatibility option setting.

PLUGIN Header Footer Elementor

CVE-2025-8488

MEDIUM CVSS 4.3 2025-08-02
Threat Entry Updated 2025-08-25

CVE-2025-6722 - Login Security Plugin

The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5 via the bitfire_* directory that automatically gets created and stores potentially sensitive files without any access restrictions. This makes it possible for unauthenticated attackers to extract sensitive data from various files like config.ini, debug.log, and more when directory listing is enabled on the server and the ~/wp-content/plugins/index.php file is missing or ignored.

PLUGIN Login Security

CVE-2025-6722

MEDIUM CVSS 5.3 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8399 - Mmm Unity Loader Plugin

The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mmm Unity Loader

CVE-2025-8399

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8400 - Bee Quick Gallery Plugin

The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bee Quick Gallery

CVE-2025-8400

MEDIUM CVSS 6.1 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8391 - Magic Edge Lite Image Background Remover Plugin

The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Magic Edge Lite Image Background Remover

CVE-2025-8391

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-6832 - Tracking Employee Time Has Never Been Easier Plugin

The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Tracking Employee Time Has Never Been Easier

CVE-2025-6832

MEDIUM CVSS 6.1 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8317 - Custom Word Cloud Plugin

The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘angle’ parameter in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Custom Word Cloud

CVE-2025-8317

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8212 - Medical Addon For Elementor Plugin

The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter widget in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Medical Addon For Elementor

CVE-2025-8212

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-6754 - Seo Metrics Helper Plugin

The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function in versions 1.0.5 through 1.0.15. Because the AJAX action only verifies a nonce, without checking the caller’s capabilities, a subscriber-level user can retrieve the token and then access the custom endpoint to obtain full administrator cookies.

PLUGIN Seo Metrics Helper

CVE-2025-6754

HIGH CVSS 8.8 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8152 - Easy Sticky Sidebar Plugin

The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_cta_status' and 'change_sticky_sidebar_name' functions in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to update the status of a sticky and update the name displayed in the back-end WP CTA Dashboard.

PLUGIN Easy Sticky Sidebar

CVE-2025-8152

MEDIUM CVSS 5.3 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-6626 - Shortpixel Adaptive Images Plugin

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Shortpixel Adaptive Images

CVE-2025-6626

MEDIUM CVSS 4.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-4588 - 360 Sphere Images Plugin

The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN 360 Sphere Images

CVE-2025-4588

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-04

CVE-2025-8146 - Qi Addons For Elementor Plugin

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut Text widget in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Qi Addons For Elementor

CVE-2025-8146

MEDIUM CVSS 6.4 2025-08-02
Threat Entry Updated 2025-08-12

CVE-2025-7694 - Woffice Plugin

The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_delete() function in all versions up to, and including, 5.4.26. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Woffice

CVE-2025-7694

MEDIUM CVSS 6.8 2025-08-02
Scroll to top