Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,596
Critical1,293
High4,448
Medium12,546
Reset
Showing 5941-5960 of 18596 records
Threat Entry Updated 2026-01-08

CVE-2025-13841 - Smart App Banners Plugin

The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalign' parameters of the 'app-store-download' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Smart App Banners

CVE-2025-13841

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13974 - Email Customizer For Woocommerce Plugin

The Email Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email template content in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in email templates that will execute when customers view transactional emails. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Email Customizer For Woocommerce

CVE-2025-13974

MEDIUM CVSS 4.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13667 - Wp Recipe Manager Plugin

The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input field in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Recipe Manager

CVE-2025-13667

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13531 - Stylish Order Form Builder Plugin

The Stylish Order Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'product_name' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Stylish Order Form Builder

CVE-2025-13531

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13722 - Conversational Form Builder Plugin

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary forms via the publicly exposed AI builder.

PLUGIN Conversational Form Builder

CVE-2025-13722

MEDIUM CVSS 5.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13694 - Aa Block Country Plugin

The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. This is due to the plugin trusting user-supplied headers such as HTTP_X_FORWARDED_FOR to determine the client's IP address without proper validation or considering if the server is behind a trusted proxy. This makes it possible for unauthenticated attackers to bypass IP-based access restrictions by spoofing their IP address via the X-Forwarded-For header.

PLUGIN Aa Block Country

CVE-2025-13694

MEDIUM CVSS 5.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13529 - Unify Plugin

The Unify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'init' action in all versions up to, and including, 3.4.9. This makes it possible for unauthenticated attackers to delete specific plugin options via the 'unify_plugin_downgrade' parameter.

PLUGIN Unify

CVE-2025-13529

MEDIUM CVSS 5.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13657 - Helpdesk Contact Form Plugin

The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation on the handle_query_args() function. This makes it possible for unauthenticated attackers to update the plugin's license ID and contact form ID settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Helpdesk Contact Form

CVE-2025-13657

MEDIUM CVSS 4.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13493 - Latest Registered Users Plugin

The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, and including, 1.4. This is due to missing authorization and nonce validation in the rnd_handle_form_submit function hooked to both admin_post_my_simple_form and admin_post_nopriv_my_simple_form actions. This makes it possible for unauthenticated attackers to export complete user details (excluding passwords and sensitive tokens) in CSV format via the 'action' parameter.

PLUGIN Latest Registered Users

CVE-2025-13493

HIGH CVSS 7.5 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13497 - Recras Wordpress Plugin

The Recras WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'recrasname' shortcode attribute in all versions up to, and including, 6.4.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Recras Wordpress

CVE-2025-13497

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13519 - Svg Map By Saedi Plugin

The SVG Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on multiple AJAX actions including 'save_data', 'delete_data', and 'add_popup'. This makes it possible for unauthenticated attackers to update the plugin's settings, delete map data, and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Svg Map By Saedi

CVE-2025-13519

MEDIUM CVSS 6.1 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13496 - Moosend Landing Pages Plugin

The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the moosend_landings_auth_get function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the 'moosend_landing_api_key' option value.

PLUGIN Moosend Landing Pages

CVE-2025-13496

MEDIUM CVSS 5.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13527 - Xshare Plugin

The xShare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing nonce validation on the 'xshare_plugin_reset()' function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Xshare

CVE-2025-13527

MEDIUM CVSS 4.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13521 - Wp Change Status Notifier Plugin

The WP Status Notifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Change Status Notifier

CVE-2025-13521

MEDIUM CVSS 4.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13520 - Mtcaptcha Wordpress Plugin

The MTCaptcha WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin settings, including sensitive values like the private key, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Mtcaptcha Wordpress

CVE-2025-13520

MEDIUM CVSS 4.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13371 - Money Space Plugin

The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.9. This is due to the plugin storing full payment card details (PAN, card holder name, expiry month/year, and CVV) in WordPress post_meta using base64_encode(), and then embedding these values into the publicly accessible mspaylink page's inline JavaScript without any authentication or authorization check. This makes it possible for unauthenticated attackers who know or can guess an order_id to access the mspaylink endpoint and retrieve full credit card numbers and CVV codes…

PLUGIN Money Space

CVE-2025-13371

HIGH CVSS 8.6 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13418 - Dk Pricr Responsive Pricing Table Plugin

The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'plan_icons' parameter in all versions up to, and including, 5.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Dk Pricr Responsive Pricing Table

CVE-2025-13418

MEDIUM CVSS 6.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13369 - Woo Customers Manager Plugin

The Premmerce WooCommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'money_spent_from', 'money_spent_to', 'registered_from', and 'registered_to' parameters in all versions up to, and including, 1.1.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into performing an action such as clicking on a link.

PLUGIN Woo Customers Manager

CVE-2025-13369

MEDIUM CVSS 6.1 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-13419 - Wp Front User Submit Plugin

The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bfe/v1/revert' REST API endpoint in all versions up to, and including, 5.0.0. This makes it possible for unauthenticated attackers to delete arbitrary media attachments.

PLUGIN Wp Front User Submit

CVE-2025-13419

MEDIUM CVSS 5.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-12648 - Wp Members Plugin

The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and including, 3.5.4.4. This is due to storing user-uploaded files in predictable directories (wp-content/uploads/wpmembers/user_files//) without implementing proper access controls beyond basic directory listing protection (.htaccess with Options -Indexes). This makes it possible for unauthenticated attackers to directly access and download sensitive documents uploaded by site users via direct URL access, granted they can guess or enumerate user IDs and filenames.

PLUGIN Wp Members

CVE-2025-12648

MEDIUM CVSS 5.3 2026-01-07
Scroll to top