Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,865
Critical1,341
High4,564
Medium12,697
Reset
Showing 8281-8300 of 18865 records
Threat Entry Updated 2025-07-07

CVE-2025-6350 - Wp Vr Plugin

The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotspot-hover’ parameter in all versions up to, and including, 8.5.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Vr

CVE-2025-6350

MEDIUM CVSS 6.4 2025-06-28
Threat Entry Updated 2025-06-30

CVE-2025-53270 - WordPress CTA Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Blend Media WordPress CTA allows Cross Site Request Forgery. This issue affects WordPress CTA: from n/a through 1.6.9.

PLUGIN WordPress CTA

CVE-2025-53270

MEDIUM CVSS 4.3 2025-06-27
Threat Entry Updated 2025-06-30

CVE-2025-53260 - Upload Of File With Dangerous Type Vulnerability In Getredhawkstudio File Manager Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in getredhawkstudio File Manager Plugin For Wordpress allows Upload a Web Shell to a Web Server. This issue affects File Manager Plugin For Wordpress: from n/a through 7.5.

PLUGIN Upload Of File With Dangerous Type Vulnerability In Getredhawkstudio File Manager

CVE-2025-53260

CRITICAL CVSS 9.1 2025-06-27
Threat Entry Updated 2025-06-30

CVE-2025-52811 - Allows Php Local File Inclusion Theme

Path Traversal vulnerability in Creanncy Davenport - Versatile Blog and Magazine WordPress Theme allows PHP Local File Inclusion. This issue affects Davenport - Versatile Blog and Magazine WordPress Theme: from n/a through 1.3.

THEME Allows Php Local File Inclusion

CVE-2025-52811

HIGH CVSS 8.1 2025-06-27
Threat Entry Updated 2025-06-30

CVE-2025-28947 - Allows Php Local File Inclusion Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme MBStore - Digital WooCommerce WordPress Theme allows PHP Local File Inclusion. This issue affects MBStore - Digital WooCommerce WordPress Theme: from n/a through 2.3.

THEME Allows Php Local File Inclusion

CVE-2025-28947

HIGH CVSS 8.1 2025-06-27
Threat Entry Updated 2025-06-30

CVE-2023-25998 - Allows Php Local File Inclusion Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme allows PHP Local File Inclusion. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.6.

THEME Allows Php Local File Inclusion

CVE-2023-25998

HIGH CVSS 8.1 2025-06-27
Threat Entry Updated 2025-07-07

CVE-2025-5398 - Ninja Forms Plugin

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ninja Forms

CVE-2025-5398

MEDIUM CVSS 6.4 2025-06-27
Threat Entry Updated 2025-07-07

CVE-2025-2940 - Ninja Tables Plugin

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via the args[url] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Ninja Tables

CVE-2025-2940

HIGH CVSS 7.2 2025-06-27
Threat Entry Updated 2025-06-30

CVE-2024-12827 - Listing Wordpress Theme

The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.6. This is due to the plugin not properly checking for an empty token value prior to resetting a user's password through the dwt_listing_reset_password() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

THEME Listing Wordpress Theme

CVE-2024-12827

CRITICAL CVSS 9.8 2025-06-27
Threat Entry Updated 2025-07-02

CVE-2025-6688 - Simple Payment Plugin

The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due to the plugin not properly verifying a user's identity prior to logging them in through the create_user() function. This makes it possible for unauthenticated attackers to log in as administrative users.

PLUGIN Simple Payment

CVE-2025-6688

CRITICAL CVSS 9.8 2025-06-27
Threat Entry Updated 2025-07-08

CVE-2025-6689 - Fl3r Accessibility Suite Plugin

The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3raccessibilitysuite shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Fl3r Accessibility Suite

CVE-2025-6689

MEDIUM CVSS 6.4 2025-06-27
Threat Entry Updated 2025-07-08

CVE-2025-6550 - Pack Elementor Addons Plugin

The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_options’ parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Pack Elementor Addons

CVE-2025-6550

MEDIUM CVSS 6.4 2025-06-27
Threat Entry Updated 2025-07-07

CVE-2025-5940 - Osom Blocks Plugin

The Osom Blocks – Custom Post Type listing block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class_name’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Osom Blocks

CVE-2025-5940

MEDIUM CVSS 6.4 2025-06-27
Threat Entry Updated 2025-06-30

CVE-2025-4587 - Ab Testing For Wp Plugin

The A/B Testing for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ab-testing-for-wp/ab-test-block' block in all versions up to, and including, 1.18.2 due to insufficient input sanitization and output escaping on the 'id' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ab Testing For Wp

CVE-2025-4587

MEDIUM CVSS 6.4 2025-06-27
Threat Entry Updated 2025-07-07

CVE-2025-5936 - Vr Calendar Plugin

The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.7. This is due to missing or incorrect nonce validation on the syncCalendar() function. This makes it possible for unauthenticated attackers to trigger a calendar sync via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Vr Calendar

CVE-2025-5936

MEDIUM CVSS 4.3 2025-06-27
Threat Entry Updated 2025-07-01

CVE-2025-5093 - Before 2 Plugin

The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and escape title attributes before outputting them back in a page/post where used, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2025-5093

MEDIUM CVSS 5.4 2025-06-27
Threat Entry Updated 2025-07-01

CVE-2025-5035 - Firelight Lightbox Plugin

The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting them in the page, which could allow users with a role as low as contributors to perform stored Cross-Site Scripting attacks.

PLUGIN Firelight Lightbox

CVE-2025-5035

MEDIUM CVSS 5.4 2025-06-27
Threat Entry Updated 2025-07-07

CVE-2025-5194 - Wp Map Block Plugin

The WP Map Block WordPress plugin before 2.0.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Wp Map Block

CVE-2025-5194

MEDIUM CVSS 4.8 2025-06-27
Threat Entry Updated 2025-07-03

CVE-2025-5526 - Buddypress Docs Plugin

The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user

PLUGIN Buddypress Docs

CVE-2025-5526

MEDIUM CVSS 4.3 2025-06-27
Threat Entry Updated 2025-06-30

CVE-2025-6488 - Ismobile Plugin

The isMobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ parameter in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ismobile

CVE-2025-6488

MEDIUM CVSS 6.4 2025-06-27
Scroll to top