Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,570
Critical1,293
High4,448
Medium12,545
Reset
Showing 5301-5320 of 18570 records
Threat Entry Updated 2026-01-14

CVE-2025-14770 - Shipping Rate By Cities Plugin

The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions up to, and including, 2.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Shipping Rate By Cities

CVE-2025-14770

HIGH CVSS 7.5 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-15376 - Stopwords For Comments Plugin

The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing nonce validation on the 'set_stopwords_for_comments' and 'delete_stopwords_for_comments' functions. This makes it possible for unauthenticated attackers to add or delete stopwords via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Stopwords For Comments

CVE-2025-15376

MEDIUM CVSS 4.3 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-14846 - Auto Post To Social Media Wp To Social Champ Plugin

The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.3. This is due to missing nonce validation on the wpsc_settings_tab_menu function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Auto Post To Social Media Wp To Social Champ

CVE-2025-14846

MEDIUM CVSS 4.3 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-14173 - Perfit Woocommerce Plugin

The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. This is due to missing authorization checks on the `logout` function called via the `actions` function hooked to `admin_init`. This makes it possible for unauthenticated attackers to delete arbitrary plugin settings via the `action` parameter.

PLUGIN Perfit Woocommerce

CVE-2025-14173

MEDIUM CVSS 5.3 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-0694 - Searchwiz Plugin

The SearchWiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in search results in all versions up to, and including, 1.0.0. This is due to the plugin using `esc_attr()` instead of `esc_html()` when outputting post titles in search results. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in post titles that will execute whenever a user performs a search and views the search results page.

PLUGIN Searchwiz

CVE-2026-0694

MEDIUM CVSS 6.4 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-0717 - Lottie Block For Gutenberg Plugin

The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.0 via the `/wp-json/lottiefiles/v1/settings/` REST API endpoint. This makes it possible for unauthenticated attackers to retrieve the site owner's LottieFiles.com account credentials including their API access token and email address when the 'Share LottieFiles account with other WordPress users' option is enabled.

PLUGIN Lottie Block For Gutenberg

CVE-2026-0717

MEDIUM CVSS 5.3 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-0678 - Flat Shipping Rate By City For Woocommerce Plugin

The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'cities' parameter in all versions up to, and including, 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Flat Shipping Rate By City For Woocommerce

CVE-2026-0678

MEDIUM CVSS 4.9 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-0680 - Real Post Slider Lite Plugin

The Real Post Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Real Post Slider Lite

CVE-2026-0680

MEDIUM CVSS 4.4 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-0635 - Responsive Accordion Slider Plugin

The Responsive Accordion Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'resp_accordion_silder_save_images' function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify any slider's image metadata including titles, descriptions, alt text, and links.

PLUGIN Responsive Accordion Slider

CVE-2026-0635

MEDIUM CVSS 4.3 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-15378 - Ajs Footnotes Plugin

The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup_display_effect_in' parameters in all versions up to, and including, 1.0 due to missing authorization and nonce verification on settings save, as well as insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to update plugin settings and inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ajs Footnotes

CVE-2025-15378

HIGH CVSS 7.2 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-15283 - Name Directory Plugin

The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and 'name_directory_description' parameters in all versions up to, and including, 1.30.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Name Directory

CVE-2025-15283

HIGH CVSS 7.2 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-0594 - List Site Contributors Plugin

The List Site Contributors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'alpha' parameter in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN List Site Contributors

CVE-2026-0594

MEDIUM CVSS 6.1 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-15486 - Kunze Law Plugin

The Kunze Law plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's shortcode in all versions up to, and including, 2.1 due to the plugin fetching HTML content from a remote server and injecting it into pages without any sanitization or escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. Additional presence of a path…

PLUGIN Kunze Law

CVE-2025-15486

MEDIUM CVSS 4.4 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-15377 - Sosh Share Buttons Plugin

The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the 'admin_page_content' function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Sosh Share Buttons

CVE-2025-15377

MEDIUM CVSS 4.3 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-15266 - Geeky Bot Plugin

The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the chat message field in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the Chat History page.

PLUGIN Geeky Bot

CVE-2025-15266

HIGH CVSS 7.2 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-14615 - Dashboard Builder Plugin

The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.7. This is due to missing nonce validation on the settings handler in dashboardbuilder-admin.php. This makes it possible for unauthenticated attackers to modify the stored SQL query and database credentials used by the [show-dashboardbuilder] shortcode via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The modified SQL query is subsequently executed on…

PLUGIN Dashboard Builder

CVE-2025-14615

HIGH CVSS 7.1 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-15020 - Gotham Block Extra Light Plugin

The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.5.0 via the 'ghostban' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Gotham Block Extra Light

CVE-2025-15020

MEDIUM CVSS 6.5 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-14854 - Wp Crm System Plugin

The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcrm_get_email_recipients and wpcrm_system_ajax_task_change_status AJAX functions in all versions up to, and including, 3.4.5. This makes it possible for authenticated attackers, with subscriber level access and above, to enumerate CRM contact email addresses (PII disclosure) and modify CRM task statuses.

PLUGIN Wp Crm System

CVE-2025-14854

MEDIUM CVSS 5.4 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-14880 - Netcash Pay Now Payment Gateway For Woocommerce Plugin

The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_return_url function in all versions up to, and including, 4.1.3. This makes it possible for unauthenticated attackers to mark any WooCommerce order as processing/completed.

PLUGIN Netcash Pay Now Payment Gateway For Woocommerce

CVE-2025-14880

MEDIUM CVSS 5.3 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-15021 - Gotham Block Extra Light Plugin

The Gotham Block Extra Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Gotham Block Extra Light

CVE-2025-15021

MEDIUM CVSS 4.4 2026-01-14
Scroll to top