Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,865
Critical1,341
High4,564
Medium12,697
Reset
Showing 8141-8160 of 18865 records
Threat Entry Updated 2025-07-22

CVE-2025-3740 - School Management System For Wordpress Plugin

The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The Local File…

PLUGIN School Management System For Wordpress

CVE-2025-3740

HIGH CVSS 8.8 2025-07-18
Threat Entry Updated 2025-07-22

CVE-2025-7431 - Knowledgebase Plugin

The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Knowledgebase

CVE-2025-7431

MEDIUM CVSS 4.4 2025-07-18
Threat Entry Updated 2026-01-23

CVE-2025-4302 - Stop User Enumeration Plugin

The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.

PLUGIN Stop User Enumeration

CVE-2025-4302

MEDIUM CVSS 5.3 2025-07-17
Threat Entry Updated 2025-07-17

CVE-2025-7712 - Madara Core Plugin

The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_delete_zip() function in all versions up to, and including, 2.2.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Madara Core

CVE-2025-7712

CRITICAL CVSS 9.1 2025-07-17
Threat Entry Updated 2025-07-17

CVE-2025-5396 - Bears Backup Plugin

The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input passed directly to call_user_func(). This makes it possible for unauthenticated attackers to execute code on the server which can be leverage to inject backdoors or create new administrative user accounts to name a few things. On WordPress sites running the Alone theme versions 7.8.4 and older, this can be chained with CVE-2025-5394 to…

PLUGIN Bears Backup

CVE-2025-5396

CRITICAL CVSS 9.8 2025-07-17
Threat Entry Updated 2025-07-16

CVE-2025-31422 - Allows Object Injection Theme

Deserialization of Untrusted Data vulnerability in designthemes Visual Art | Gallery WordPress Theme allows Object Injection. This issue affects Visual Art | Gallery WordPress Theme: from n/a through 2.4.

THEME Allows Object Injection

CVE-2025-31422

HIGH CVSS 8.8 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-47554 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress allows Reflected XSS. This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through 11.6.

CORE WordPress Core

CVE-2025-47554

HIGH CVSS 7.1 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-46500 - Wordpress Auto Spinner Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Wordpress Auto Spinner allows Reflected XSS. This issue affects Wordpress Auto Spinner: from n/a through 3.25.0.

PLUGIN Wordpress Auto Spinner

CVE-2025-46500

HIGH CVSS 7.1 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-31427 - Invico - WordPress Consulting Business Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Invico - WordPress Consulting Business Theme allows Reflected XSS. This issue affects Invico - WordPress Consulting Business Theme: from n/a through 1.9.

THEME Invico - WordPress Consulting Business Theme

CVE-2025-31427

HIGH CVSS 7.1 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-31072 - Ofiz - WordPress Business Consulting Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Ofiz - WordPress Business Consulting Theme allows Reflected XSS. This issue affects Ofiz - WordPress Business Consulting Theme: from n/a through 2.0.

THEME Ofiz - WordPress Business Consulting Theme

CVE-2025-31072

HIGH CVSS 7.1 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-31055 - Electrician - Electrical Service WordPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vergatheme Electrician - Electrical Service WordPress allows Reflected XSS. This issue affects Electrician - Electrical Service WordPress: from n/a through 1.0.

PLUGIN Electrician - Electrical Service WordPress

CVE-2025-31055

HIGH CVSS 7.1 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-24759 - WP-BusinessDirectory Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory allows Blind SQL Injection. This issue affects WP-BusinessDirectory: from n/a through 3.1.3.

PLUGIN WP-BusinessDirectory

CVE-2025-24759

CRITICAL CVSS 9.3 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-28955 - WooCommerce Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FWDesign Easy Video Player Wordpress & WooCommerce allows Path Traversal. This issue affects Easy Video Player Wordpress & WooCommerce: from n/a through 10.0.

PLUGIN WooCommerce

CVE-2025-28955

HIGH CVSS 7.5 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-48294 - FG Drupal to WordPress Plugin

Server-Side Request Forgery (SSRF) vulnerability in Kerfred FG Drupal to WordPress allows Server Side Request Forgery. This issue affects FG Drupal to WordPress: from n/a through 3.90.0.

PLUGIN FG Drupal to WordPress

CVE-2025-48294

MEDIUM CVSS 4.4 2025-07-16
Threat Entry Updated 2025-08-02

CVE-2025-6993 - Ultimate Wp Mail Plugin

The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX handler in versions 1.0.17 to 1.3.6. The handler reads the client-supplied post_id and retrieves the corresponding email log post content (including the password-reset link), relying only on the ‘edit_posts’ capability without restricting to administrators or validating ownership. This makes it possible for authenticated attackers, with Contributor-level access and above, to harvest an admin’s reset link and elevate their privileges to administrator.

PLUGIN Ultimate Wp Mail

CVE-2025-6993

HIGH CVSS 7.5 2025-07-16
Threat Entry Updated 2025-07-23

CVE-2025-7035 - Media Library Assistant Plugin

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_cloud and mla_term_list shortcodes in all versions up to, and including, 3.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Media Library Assistant

CVE-2025-7035

MEDIUM CVSS 6.4 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-5284 - Master Addons Plugin

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS extension in all versions up to, and including, 2.0.8.2 due to insufficient capability restriction, and insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Master Addons

CVE-2025-5284

MEDIUM CVSS 6.4 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-7359 - Counter Visitor For Woocommerce Plugin

The Counter live visitors for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wcvisitor_get_block function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers to delete arbitrary files on the server. NOTE: This particular vulnerability deletes all the files in a targeted arbitrary directory rather than a specified arbitrary file, which can lead to loss of data or a denial of service condition.

PLUGIN Counter Visitor For Woocommerce

CVE-2025-7359

HIGH CVSS 8.2 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-6747 - Builder Plugin

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusion_map' shortcode in all versions up to, and including, 3.12.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Builder

CVE-2025-6747

MEDIUM CVSS 6.4 2025-07-16
Threat Entry Updated 2025-07-16

CVE-2025-6043 - Wp Malware Removal Plugin

The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Deletion due to a missing capability check on the wpmr_delete_file() function in all versions up to, and including, 16.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files making remote code execution possible. This is only exploitable when advanced mode is enabled on the site.

PLUGIN Wp Malware Removal

CVE-2025-6043

HIGH CVSS 8.1 2025-07-16
Scroll to top