Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,596
Critical1,293
High4,448
Medium12,546
Reset
Showing 6081-6100 of 18596 records
Threat Entry Updated 2026-01-02

CVE-2025-14627 - Wp Ultimate Csv Importer Plugin

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after following Bitly shortlink redirects in the `upload_function()` method. While the initial URL is validated using `wp_http_validate_url()`, when a Bitly shortlink is detected, the `unshorten_bitly_url()` function follows redirects to the final destination URL without re-validating it. This makes it possible for authenticated attackers with Contributor-level access or higher to make the server perform…

PLUGIN Wp Ultimate Csv Importer

CVE-2025-14627

MEDIUM CVSS 6.4 2026-01-01
Threat Entry Updated 2026-01-02

CVE-2025-14428 - Mystickyelements Plugin

The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function in all versions up to, and including, 2.3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all contact form leads stored by the plugin.

PLUGIN Mystickyelements

CVE-2025-14428

MEDIUM CVSS 4.3 2026-01-01
Threat Entry Updated 2026-01-06

CVE-2026-0544 - School Management System Plugin

A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

PLUGIN School Management System

CVE-2026-0544

MEDIUM CVSS 6.9 2026-01-01
Threat Entry Updated 2026-01-05

CVE-2025-13820 - Before 7 Plugin

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

PLUGIN Before 7

CVE-2025-13820

MEDIUM CVSS 5.3 2026-01-01
Threat Entry Updated 2026-01-20

CVE-2025-28949 - Mediabay - WordPress Media Library Folders Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4.

PLUGIN Mediabay - WordPress Media Library Folders

CVE-2025-28949

HIGH CVSS 8.5 2025-12-31
Threat Entry Updated 2026-01-20

CVE-2025-62088 - WooCommerce Plugin

Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site allows Server Side Request Forgery.This issue affects WordPress & WooCommerce Scraper Plugin, Import Data from Any Site: from n/a through 1.0.7.

PLUGIN WooCommerce

CVE-2025-62088

MEDIUM CVSS 5.4 2025-12-31
Threat Entry Updated 2026-01-20

CVE-2025-62083 - BoomDevs WordPress Coming Soon Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah BoomDevs WordPress Coming Soon Plugin allows Retrieve Embedded Sensitive Data.This issue affects BoomDevs WordPress Coming Soon Plugin: from n/a through 1.0.4.

PLUGIN BoomDevs WordPress Coming Soon Plugin

CVE-2025-62083

MEDIUM CVSS 4.3 2025-12-31
Threat Entry Updated 2026-01-20

CVE-2025-63005 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomas WordPress Tooltips allows Stored XSS.This issue affects WordPress Tooltips: from n/a through 10.7.9.

CORE WordPress Core

CVE-2025-63005

MEDIUM CVSS 6.5 2025-12-31
Threat Entry Updated 2025-12-31

CVE-2025-14783 - Easy Digital Downloads Plugin

The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the password reset email to potentially malicious sites if they can successfully trick them into performing an action.

PLUGIN Easy Digital Downloads

CVE-2025-14783

MEDIUM CVSS 4.3 2025-12-31
Threat Entry Updated 2026-01-02

CVE-2025-14434 - Ultimate Post Kit Addons For Elementor Plugin

The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX “load more” endpoints such as upk_alex_grid_loadmore_posts without ensuring that posts to be displayed are published authentication. This allows an unauthenticated attacker to query arbitrary posts and retrieve rendered HTML content of private and unpublished ones.

PLUGIN Ultimate Post Kit Addons For Elementor

CVE-2025-14434

MEDIUM CVSS 5.3 2025-12-31
Threat Entry Updated 2026-01-20

CVE-2025-52835 - WING WordPress Migrator Plugin

Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator allows Upload a Web Shell to a Web Server.This issue affects WING WordPress Migrator: from n/a through 1.1.9.

PLUGIN WING WordPress Migrator

CVE-2025-52835

CRITICAL CVSS 9.6 2025-12-30
Threat Entry Updated 2026-01-20

CVE-2025-62746 - Featured Video for WordPress & VideographyWP Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeFlavors Featured Video for WordPress & VideographyWP allows Stored XSS.This issue affects Featured Video for WordPress & VideographyWP: from n/a through 1.0.18.

PLUGIN Featured Video for WordPress & VideographyWP

CVE-2025-62746

MEDIUM CVSS 6.5 2025-12-30
Threat Entry Updated 2025-12-31

CVE-2025-14426 - Strong Testimonials Plugin

The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'edit_rating' function in all versions up to, and including, 3.2.18. This makes it possible for authenticated attackers with Contributor-level access and above to modify or delete the rating meta on any testimonial post, including those created by other users, by reusing a valid nonce obtained from their own testimonial edit screen.

PLUGIN Strong Testimonials

CVE-2025-14426

MEDIUM CVSS 4.3 2025-12-30
Threat Entry Updated 2025-12-31

CVE-2025-14509 - Woo Lucky Wheel Plugin

The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.1.13. This is due to the plugin using eval() to execute user-supplied input from the 'Conditional Tags' setting without proper validation or sanitization. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server. In WordPress multisite installations, this allows Site Administrators to execute arbitrary code, a capability they should not have since plugin/theme file editing…

PLUGIN Woo Lucky Wheel

CVE-2025-14509

HIGH CVSS 7.2 2025-12-30
Threat Entry Updated 2026-01-20

CVE-2025-69022 - HR Management Lite Plugin

Missing Authorization vulnerability in Weblizar - WordPress Themes & Plugin HR Management Lite hr-management-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HR Management Lite: from n/a through

PLUGIN HR Management Lite

CVE-2025-69022

MEDIUM CVSS 5.4 2025-12-30
Threat Entry Updated 2026-01-20

CVE-2025-68987 - For Movie Studios And Filmmakers Cinerama Allows Php Local File Inclusion Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Cinerama - A WordPress Theme for Movie Studios and Filmmakers cinerama allows PHP Local File Inclusion.This issue affects Cinerama - A WordPress Theme for Movie Studios and Filmmakers: from n/a through

THEME For Movie Studios And Filmmakers Cinerama Allows Php Local File Inclusion

CVE-2025-68987

CRITICAL CVSS 9.8 2025-12-30
Threat Entry Updated 2026-01-20

CVE-2025-68974 - WordPress Core

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through

CORE WordPress Core

CVE-2025-68974

CRITICAL CVSS 9.8 2025-12-30
Threat Entry Updated 2025-12-31

CVE-2025-14313 - Advance Wp Query Search Filter Plugin

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Advance Wp Query Search Filter

CVE-2025-14313

MEDIUM CVSS 6.1 2025-12-30
Scroll to top