Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,596
Critical1,293
High4,448
Medium12,546
Reset
Showing 5961-5980 of 18596 records
Threat Entry Updated 2026-01-08

CVE-2025-12958 - Rankology Seo And Analytics Tool Plugin

The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect capability check on the 'rankology_code_block' page in all versions up to, and including, 2.0. This makes it possible for authenticated attackers, with Editor-level access and above, to add header and footer code blocks.

PLUGIN Rankology Seo And Analytics Tool

CVE-2025-12958

LOW CVSS 2.7 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-12449 - Wordpress Gutenberg Blocks Plugin

The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible for authenticated attackers, with subscriber level access and above, to read plugin settings including block visibility, maintenance mode configuration, and third-party email marketing API keys, as well as read sensitive configuration data including API keys for email marketing services.

PLUGIN Wordpress Gutenberg Blocks

CVE-2025-12449

MEDIUM CVSS 5.4 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-12540 - Googleanalytics Plugin

The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.4. This is due to the Google Analytics client_ID and client_secret being stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to craft a link to the sharethis.com server, which will share an authorization token for Google Analytics with a malicious website, if the attacker can trick an administrator logged into the website and Google Analytics to click the link.

PLUGIN Googleanalytics

CVE-2025-12540

MEDIUM CVSS 4.7 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-12030 - Acf To Rest Api Plugin

The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.4. This is due to insufficient capability checks in the update_item_permissions_check() method, which only verifies that the current user has the edit_posts capability without checking object-specific permissions (e.g., edit_post($id), edit_user($id), manage_options). This makes it possible for authenticated attackers, with Contributor-level access and above, to modify ACF fields on posts they do not own, any user account, comments, taxonomy terms, and even the global options page via the /wp-json/acf/v3/{type}/{id}…

PLUGIN Acf To Rest Api

CVE-2025-12030

MEDIUM CVSS 4.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-31051 - Allows Retrieve Embedded Sensitive Data Theme

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EngoTheme Plant - Gardening & Houseplants WordPress Theme allows Retrieve Embedded Sensitive Data.This issue affects Plant - Gardening & Houseplants WordPress Theme: from n/a through 1.0.0.

THEME Allows Retrieve Embedded Sensitive Data

CVE-2025-31051

MEDIUM CVSS 5.3 2026-01-07
Threat Entry Updated 2026-01-12

CVE-2026-21492 - iccDEV Plugin

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a NULL pointer member call vulnerability. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.

PLUGIN iccDEV

CVE-2026-21492

MEDIUM CVSS 5.5 2026-01-06
Threat Entry Updated 2026-01-08

CVE-2025-30996 - Cted Upload Of File With Dangerous Type Vulnerability In Themify Themify Sidepane Theme

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects Themify Sidepane WordPress Theme: from n/a through 1.9.8; Themify Newsy: from n/a through 1.9.9; Themify Folo: from n/a through 1.9.6; Themify Edmin: from n/a through 2.0.0; Bloggie: from n/a through 2.0.8; Photobox: from n/a through 2.0.1; Wigi: from n/a through 2.0.1; Rezo: from n/a through 1.9.7;…

THEME Cted Upload Of File With Dangerous Type Vulnerability In Themify Themify Sidepane

CVE-2025-30996

CRITICAL CVSS 9.9 2026-01-06
Threat Entry Updated 2026-01-08

CVE-2025-29004 - Premium Age Verification / Restriction for WordPress Plugin

Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through 3.0.

PLUGIN Premium Age Verification / Restriction for WordPress

CVE-2025-29004

HIGH CVSS 8.8 2026-01-06
Threat Entry Updated 2026-01-12

CVE-2026-21494 - iccDEV Plugin

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It results in heap buffer overflow in `CIccTagLut8::Validate()`. Version 2.3.1.2 contains a patch. No known workarounds are available.

PLUGIN iccDEV

CVE-2026-21494

MEDIUM CVSS 6.1 2026-01-06
Threat Entry Updated 2026-01-12

CVE-2026-21491 - iccDEV Plugin

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It results in unicode buffer overflow in `CIccTagTextDescription`. Version 2.3.1.2 contains a patch. No known workarounds are available.

PLUGIN iccDEV

CVE-2026-21491

MEDIUM CVSS 6.1 2026-01-06
Threat Entry Updated 2026-01-12

CVE-2026-21490 - iccDEV Plugin

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It results in heap buffer overflow in `CIccTagLut16::Validate()`. Version 2.3.1.2 contains a patch. No known workarounds are available.

PLUGIN iccDEV

CVE-2026-21490

MEDIUM CVSS 6.1 2026-01-06
Threat Entry Updated 2026-01-22

CVE-2026-0641 - WA300 Plugin

A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. The manipulation of the argument UPLOAD_FILENAME leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

PLUGIN WA300

CVE-2026-0641

MEDIUM CVSS 5.3 2026-01-06
Threat Entry Updated 2026-01-20

CVE-2025-69331 - WordPress Core

Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through

CORE WordPress Core

CVE-2025-69331

MEDIUM CVSS 4.3 2026-01-06
Threat Entry Updated 2026-01-15

CVE-2026-0640 - AC23 Plugin

A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

PLUGIN AC23

CVE-2026-0640

HIGH CVSS 7.4 2026-01-06
Threat Entry Updated 2026-01-14

CVE-2026-21493 - iccDEV Plugin

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.

PLUGIN iccDEV

CVE-2026-21493

MEDIUM CVSS 6.6 2026-01-06
Threat Entry Updated 2026-01-14

CVE-2026-21489 - iccDEV Plugin

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have Out-of-bounds Read and Integer Underflow (Wrap or Wraparound) vulnerabilities in its CIccCalculatorFunc::SequenceNeedTempReset function. This issue is fixed in version 2.3.1.2.

PLUGIN iccDEV

CVE-2026-21489

MEDIUM CVSS 6.1 2026-01-06
Threat Entry Updated 2026-01-14

CVE-2026-21488 - iccDEV Plugin

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Out-of-bounds Read, Heap-based Buffer Overflow and Improper Null Termination through its CIccTagText::Read function. This issue is fixed in version 2.3.1.2.

PLUGIN iccDEV

CVE-2026-21488

MEDIUM CVSS 6.1 2026-01-06
Threat Entry Updated 2026-01-09

CVE-2025-9637 - Quiz Master Next Plugin

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all versions up to, and including, 10.3.1. This makes it possible for unauthenticated attackers to view the details of unpublished, private, or password-protected quizzes, as well as submit file responses to questions from those quizzes, which allow file upload.

PLUGIN Quiz Master Next

CVE-2025-9637

MEDIUM CVSS 6.5 2026-01-06
Threat Entry Updated 2026-01-09

CVE-2025-9318 - Quiz Master Next Plugin

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Quiz Master Next

CVE-2025-9318

MEDIUM CVSS 6.5 2026-01-06
Threat Entry Updated 2026-01-08

CVE-2025-14552 - Mediapress Plugin

The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mediapress

CVE-2025-14552

MEDIUM CVSS 6.4 2026-01-06
Scroll to top