Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 5841-5860 of 15036 records
Threat Entry Updated 2025-02-28

CVE-2024-13494 - Wordpress File Upload Plugin

The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the 'wfu_file_details' function. This makes it possible for unauthenticated attackers to modify user data details associated with uploaded files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wordpress File Upload

CVE-2024-13494

MEDIUM CVSS 4.3 2025-02-25
Threat Entry Updated 2025-02-28

CVE-2025-1128 - Everest Forms Plugin

The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including, 3.0.9.4. This makes it possible for unauthenticated attackers to upload, read, and delete arbitrary files on the affected site's server which may make remote code execution, sensitive information disclosure, or a site takeover possible.

PLUGIN Everest Forms

CVE-2025-1128

CRITICAL CVSS 9.8 2025-02-25
Threat Entry Updated 2025-02-28

CVE-2025-1648 - Yawave Plugin

The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Yawave

CVE-2025-1648

HIGH CVSS 7.5 2025-02-25
Threat Entry Updated 2025-02-28

CVE-2025-1063 - Classified Listing Plugin

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.4 via the rtcl_taxonomy_settings_export function. This makes it possible for unauthenticated attackers to extract sensitive data including API keys and tokens.

PLUGIN Classified Listing

CVE-2025-1063

MEDIUM CVSS 5.3 2025-02-25
Threat Entry Updated 2025-05-15

CVE-2024-10545 - Proofing And Plugin

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Proofing And

CVE-2024-10545

LOW CVSS 3.5 2025-02-25
Threat Entry Updated 2025-02-24

CVE-2025-27265 - Google Maps for WordPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aaron D. Campbell Google Maps for WordPress allows DOM-Based XSS. This issue affects Google Maps for WordPress: from n/a through 1.0.3.

PLUGIN Google Maps for WordPress

CVE-2025-27265

MEDIUM CVSS 6.5 2025-02-24
Threat Entry Updated 2025-03-27

CVE-2025-1488 - Wpo365 Msgraphmailer Plugin

The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if 1. they can successfully trick them into performing an action and 2. the plugin is activated but not configured.

PLUGIN Wpo365 Msgraphmailer

CVE-2025-1488

MEDIUM CVSS 4.7 2025-02-24
Threat Entry Updated 2025-05-07

CVE-2024-13822 - Totalcontest Plugin

The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Totalcontest

CVE-2024-13822

MEDIUM CVSS 6.1 2025-02-24
Threat Entry Updated 2025-05-07

CVE-2024-13605 - Form Maker By 10web Plugin

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Form Maker By 10web

CVE-2024-13605

MEDIUM CVSS 4.8 2025-02-24
Threat Entry Updated 2025-05-07

CVE-2024-12308 - Before 4 Plugin

The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 4

CVE-2024-12308

MEDIUM CVSS 5.4 2025-02-24
Threat Entry Updated 2025-02-23

CVE-2024-13728 - Easy Paypal Donation Plugin

The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Easy Paypal Donation

CVE-2024-13728

MEDIUM CVSS 6.1 2025-02-23
Threat Entry Updated 2025-02-22

CVE-2025-0957 - SMTP for Amazon SES – YaySMTP Plugin

The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN SMTP for Amazon SES – YaySMTP

CVE-2025-0957

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-05

CVE-2025-0953 - Yaysmtp Plugin

The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Yaysmtp

CVE-2025-0953

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-05

CVE-2025-0918 - Yaysmtp Plugin

The SMTP for SendGrid – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Yaysmtp

CVE-2025-0918

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-05

CVE-2024-13869 - Wpvivid Backup Migration Plugin

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload folder prevents…

PLUGIN Wpvivid Backup Migration

CVE-2024-13869

HIGH CVSS 7.2 2025-02-22
Threat Entry Updated 2025-03-06

CVE-2025-1361 - Country Blocker Plugin

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.

PLUGIN Country Blocker

CVE-2025-1361

HIGH CVSS 7.5 2025-02-22
Threat Entry Updated 2025-03-18

CVE-2024-13564 - Rife Elementor Extensions Templates Plugin

The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rife Elementor Extensions Templates

CVE-2024-13564

MEDIUM CVSS 6.4 2025-02-22
Threat Entry Updated 2025-02-22

CVE-2024-13474 - Purolator Edition Plugin

The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Purolator Edition

CVE-2024-13474

HIGH CVSS 7.5 2025-02-22
Threat Entry Updated 2025-03-06

CVE-2024-12038 - Buddyforms Plugin

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buddyforms_nav' shortcode in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Buddyforms

CVE-2024-12038

MEDIUM CVSS 6.4 2025-02-22
Threat Entry Updated 2025-03-07

CVE-2024-12467 - Payment By Redsys Plugin

The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters' parameter in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Payment By Redsys

CVE-2024-12467

MEDIUM CVSS 6.1 2025-02-22
Scroll to top