Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 4181-4200 of 15036 records
Threat Entry Updated 2025-08-04

CVE-2025-6228 - Sina Extension For Elementor Plugin

The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `Sina Posts`, `Sina Blog Post` and `Sina Table` widgets in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sina Extension For Elementor

CVE-2025-6228

MEDIUM CVSS 6.4 2025-08-01
Threat Entry Updated 2025-08-04

CVE-2025-4684 - No Coding Needed Plugin

The BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attributes of Image Carousel and Image Slider widgets in all versions up to, and including, 3.2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected…

PLUGIN No Coding Needed

CVE-2025-4684

MEDIUM CVSS 6.4 2025-08-01
Threat Entry Updated 2025-08-04

CVE-2025-7646 - Plus Addons For Elementor Page Builder Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom script parameter in all versions up to, and including, 6.3.10 even when the user does not have the unfiltered_html capability. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor Page Builder

CVE-2025-7646

MEDIUM CVSS 6.4 2025-08-01
Threat Entry Updated 2025-08-06

CVE-2025-5921 - Before 1 Plugin

The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.

PLUGIN Before 1

CVE-2025-5921

MEDIUM CVSS 5.8 2025-08-01
Threat Entry Updated 2025-08-04

CVE-2025-7845 - Elementor Widgets Plugin

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Google Maps and Image Hotspot widgets in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elementor Widgets

CVE-2025-7845

MEDIUM CVSS 6.4 2025-08-01
Threat Entry Updated 2025-08-04

CVE-2025-7443 - And Javascript Plugin

The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the store_javascript_cache.php file in all versions up to, and including, 2.2.42. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN And Javascript

CVE-2025-7443

HIGH CVSS 8.1 2025-08-01
Threat Entry Updated 2025-08-04

CVE-2025-7725 - Openai Plugin

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment feature in all versions up to, and including, 26.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Openai

CVE-2025-7725

HIGH CVSS 7.2 2025-08-01
Threat Entry Updated 2025-12-05

CVE-2025-4523 - Idonate Plugin

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the admin_donor_profile_view() function in versions 2.0.0 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to expose an administrator’s username, email address, and all donor fields.

PLUGIN Idonate

CVE-2025-4523

MEDIUM CVSS 6.5 2025-08-01
Threat Entry Updated 2025-10-23

CVE-2025-5947 - Service Finder Bookings Plugin

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to logging them in through the service_finder_switch_back() function. This makes it possible for unauthenticated attackers to login as any user including admins.

PLUGIN Service Finder Bookings

CVE-2025-5947

CRITICAL CVSS 9.8 2025-08-01
Threat Entry Updated 2025-08-04

CVE-2025-5954 - Service Finder Sms System Plugin

The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not restricting user role selection at the time of registration through the aonesms_fn_savedata_after_signup() function. This makes it possible for unauthenticated attackers to register as an administrator user.

PLUGIN Service Finder Sms System

CVE-2025-5954

CRITICAL CVSS 9.8 2025-08-01
Threat Entry Updated 2025-07-31

CVE-2025-8213 - Malware Scan Plugin

The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'nscan_ajax_quarantine' and 'nscan_quarantine_select' functions in all versions up to, and including, 3.2.5. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, including files outside the WordPress root directory.

PLUGIN Malware Scan

CVE-2025-8213

HIGH CVSS 7.2 2025-07-31
Threat Entry Updated 2025-08-13

CVE-2025-8401 - Ht Mega Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including the content of private, password-protected, and draft posts and pages.

PLUGIN Ht Mega

CVE-2025-8401

MEDIUM CVSS 4.3 2025-07-31
Threat Entry Updated 2025-08-13

CVE-2025-8151 - Ht Mega Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1 via the 'save_block_css' function. This makes it possible for authenticated attackers, with Author-level access and above, to create CSS files in any directory, and delete CSS files in any directory in a Windows environment.

PLUGIN Ht Mega

CVE-2025-8151

MEDIUM CVSS 4.3 2025-07-31
Threat Entry Updated 2025-08-13

CVE-2025-8068 - Ht Mega Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash_templates' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary attachment files, and move arbitrary posts, pages, and templates to the Trash.

PLUGIN Ht Mega

CVE-2025-8068

MEDIUM CVSS 4.3 2025-07-31
Threat Entry Updated 2025-08-13

CVE-2025-7205 - Givewp Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the donor notes parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with GiveWP worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Additionally, they need to trick an administrator into visiting the legacy version of the site.

PLUGIN Givewp

CVE-2025-7205

MEDIUM CVSS 5.4 2025-07-31
Threat Entry Updated 2025-07-31

CVE-2025-7847 - Ai Engine Plugin

The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server when the REST API is enabled, which may make remote code execution possible.

PLUGIN Ai Engine

CVE-2025-7847

HIGH CVSS 8.8 2025-07-31
Threat Entry Updated 2025-07-31

CVE-2025-5720 - Customer Reviews Woocommerce Plugin

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 5.80.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Customer Reviews Woocommerce

CVE-2025-5720

MEDIUM CVSS 6.4 2025-07-31
Threat Entry Updated 2025-07-31

CVE-2025-6348 - Smart Slider 3 Plugin

The Smart Slider 3 plugin for WordPress is vulnerable to time-based SQL Injection via the ‘sliderid’ parameter in all versions up to, and including, 3.5.1.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Smart Slider 3

CVE-2025-6348

MEDIUM CVSS 4.9 2025-07-30
Threat Entry Updated 2025-07-31

CVE-2025-5684 - Custom Form Builder For Elementor Plugin

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `mf-template` DOM Element in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Custom Form Builder For Elementor

CVE-2025-5684

MEDIUM CVSS 6.4 2025-07-29
Threat Entry Updated 2025-07-29

CVE-2025-5587 - Appzend Theme

The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Appzend

CVE-2025-5587

MEDIUM CVSS 6.4 2025-07-29
Scroll to top