Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,865
Critical1,341
High4,564
Medium12,697
Reset
Showing 8361-8380 of 18865 records
Threat Entry Updated 2025-06-17

CVE-2025-5673 - Blog2social Plugin

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the ‘prgSortPostType’ parameter in all versions up to, and including, 8.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Blog2social

CVE-2025-5673

MEDIUM CVSS 6.5 2025-06-17
Threat Entry Updated 2025-06-17

CVE-2025-4775 - Ajax Load More Plugin

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ajax Load More

CVE-2025-4775

MEDIUM CVSS 6.4 2025-06-17
Threat Entry Updated 2025-06-17

CVE-2025-3774 - Wise Chat Plugin

The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wise Chat

CVE-2025-3774

HIGH CVSS 7.2 2025-06-17
Threat Entry Updated 2025-07-09

CVE-2025-5337 - Slider Gallery And Carousel Plugin

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slider Gallery And Carousel

CVE-2025-5337

MEDIUM CVSS 6.4 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-5238 - Yith Woocommerce Wishlist Plugin

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Yith Woocommerce Wishlist

CVE-2025-5238

MEDIUM CVSS 6.4 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-4667 - Simply Schedule Appointments Plugin

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments shortcodes in all versions up to, and including, 1.6.8.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simply Schedule Appointments

CVE-2025-4667

MEDIUM CVSS 6.4 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6065 - Image Resizer On The Fly Plugin

The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' task in all versions up to, and including, 1.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Image Resizer On The Fly

CVE-2025-6065

CRITICAL CVSS 9.1 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6070 - Restrict File Access Plugin

The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Restrict File Access

CVE-2025-6070

MEDIUM CVSS 6.5 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6061 - Kk Youtube Video Plugin

The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Kk Youtube Video

CVE-2025-6061

MEDIUM CVSS 6.4 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6064 - Wp Url Shortener Plugin

The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the 'url_shortener_settings' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Url Shortener

CVE-2025-6064

MEDIUM CVSS 6.1 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6063 - Xisearch Bar Plugin

The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing or incorrect nonce validation on the 'xisearch-key-config' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Xisearch Bar

CVE-2025-6063

MEDIUM CVSS 6.1 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6055 - Zen Social Sticky Plugin

The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing or incorrect nonce validation on the 'zen-social-sticky/zen-sticky-social.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Zen Social Sticky

CVE-2025-6055

MEDIUM CVSS 6.1 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6062 - Yougler Blogger Profile Page Plugin

The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due to missing or incorrect nonce validation on the 'yougler-plugin.php' page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Yougler Blogger Profile Page

CVE-2025-6062

MEDIUM CVSS 4.3 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-5589 - Streamweasels Kick Integration Plugin

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Streamweasels Kick Integration

CVE-2025-5589

MEDIUM CVSS 6.4 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-5336 - Click To Chat For Whatsapp Plugin

The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter in all versions up to, and including, 4.22 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Click To Chat For Whatsapp

CVE-2025-5336

MEDIUM CVSS 6.4 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-4216 - Ecava Diot Scada Plugin

The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and including, 1.0.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ecava Diot Scada

CVE-2025-4216

MEDIUM CVSS 6.4 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-6040 - Easy Flashcards Plugin

The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing or incorrect nonce validation on the 'ef_settings_submenu' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Easy Flashcards

CVE-2025-6040

MEDIUM CVSS 6.1 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-4592 - Ai Image Generator Lab Plugin

The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the 'wpz-ai-images' page. This makes it possible for unauthenticated attackers to update the plugin's API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ai Image Generator Lab

CVE-2025-4592

MEDIUM CVSS 4.3 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-4200 - Accessories Woocommerce Wordpress Theme

The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.1 via the load_view() function that is called via at least three AJAX actions: 'load_more_post', 'load_shop', and 'load_more_product. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other…

THEME Accessories Woocommerce Wordpress Theme

CVE-2025-4200

HIGH CVSS 8.1 2025-06-14
Threat Entry Updated 2025-06-16

CVE-2025-4187 - Userpro Community And User Profile Plugin

The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 via the userpro_fbconnect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Userpro Community And User Profile

CVE-2025-4187

MEDIUM CVSS 5.9 2025-06-14
Scroll to top