Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,865
Critical1,341
High4,564
Medium12,697
Reset
Showing 8401-8420 of 18865 records
Threat Entry Updated 2025-06-12

CVE-2025-6003 - WordPress component

The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions up to, and including, the *.5.3 versions of the plugin. This makes it possible for unauthenticated attackers to extract sensitive data including site content that has been restricted to certain users and/or roles.

UNKNOWN WordPress component

CVE-2025-6003

MEDIUM CVSS 5.3 2025-06-12
Threat Entry Updated 2025-07-10

CVE-2025-4973 - Workreap Plugin

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. This is due to the plugin not properly verifying a user's identity prior to logging them in when verifying an account with an email address. This makes it possible for unauthenticated attackers to log in as registered users, including administrators, if they know user's email address. This is only exploitable fi the user's confirmation_key has not already been set by the plugin.

PLUGIN Workreap

CVE-2025-4973

CRITICAL CVSS 9.8 2025-06-12
Threat Entry Updated 2025-07-10

CVE-2025-5012 - Workreap Plugin

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'workreap_temp_upload_to_media' function in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Workreap

CVE-2025-5012

HIGH CVSS 8.8 2025-06-12
Threat Entry Updated 2025-07-10

CVE-2025-5144 - The Events Calendar Plugin

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN The Events Calendar

CVE-2025-5144

MEDIUM CVSS 6.4 2025-06-11
Threat Entry Updated 2025-06-12

CVE-2025-3302 - Xagio Seo Plugin

The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ parameter in all versions up to, and including, 7.1.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 7.1.0.0.

PLUGIN Xagio Seo

CVE-2025-3302

HIGH CVSS 7.2 2025-06-11
Threat Entry Updated 2025-07-10

CVE-2025-4315 - Cubewp Plugin

The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user to update arbitrary user meta through the update_user_meta() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

PLUGIN Cubewp

CVE-2025-4315

HIGH CVSS 8.8 2025-06-11
Threat Entry Updated 2025-06-12

CVE-2025-5395 - Wordpress Automatic Plugin

The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'core.php' file in all versions up to, and including, 3.115.0. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wordpress Automatic

CVE-2025-5395

HIGH CVSS 8.8 2025-06-11
Threat Entry Updated 2025-07-09

CVE-2025-4799 - Wp Downloadmanager Plugin

The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This vulnerability can be paired with CVE-2025-4798 to delete any file within the WordPress root directory.

PLUGIN Wp Downloadmanager

CVE-2025-4799

HIGH CVSS 7.2 2025-06-11
Threat Entry Updated 2025-07-09

CVE-2025-4798 - Wp Downloadmanager Plugin

The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storing downloads. This makes it possible for authenticated attackers, with Administrator-level access and above, to download and read any file on the server, including system and configuration files.

PLUGIN Wp Downloadmanager

CVE-2025-4798

MEDIUM CVSS 4.9 2025-06-11
Threat Entry Updated 2025-06-12

CVE-2025-4666 - Zotpress Plugin

The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nickname’ parameter in all versions up to, and including, 7.3.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Zotpress

CVE-2025-4666

MEDIUM CVSS 6.4 2025-06-11
Threat Entry Updated 2025-07-16

CVE-2025-4774 - Premium Addons For Elementor Plugin

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdown attribute of Countdown widget in all versions up to, and including, 4.11.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Premium Addons For Elementor

CVE-2025-4774

MEDIUM CVSS 6.4 2025-06-10
Threat Entry Updated 2025-07-16

CVE-2025-4577 - Smash Balloon Social Post Feed Plugin

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-color attribute in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Smash Balloon Social Post Feed

CVE-2025-4577

MEDIUM CVSS 6.4 2025-06-10
Threat Entry Updated 2025-07-14

CVE-2025-2918 - Ultimate Blocks Plugin

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Blocks

CVE-2025-2918

MEDIUM CVSS 6.4 2025-06-10
Threat Entry Updated 2025-07-02

CVE-2025-4954 - Axle Demo Importer Plugin

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server

PLUGIN Axle Demo Importer

CVE-2025-4954

HIGH CVSS 8.8 2025-06-10
Threat Entry Updated 2025-07-02

CVE-2025-4840 - Likes And Dislikes Plugin

The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN Likes And Dislikes

CVE-2025-4840

HIGH CVSS 7.5 2025-06-10
Threat Entry Updated 2025-07-11

CVE-2025-3076 - Elementor Page Builder Plugin

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text’ parameter in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elementor Page Builder

CVE-2025-3076

MEDIUM CVSS 6.4 2025-06-10
Threat Entry Updated 2025-06-12

CVE-2025-5925 - Bunnys Print Css Plugin

The Bunny’s Print CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.95. This is due to missing or incorrect nonce validation on the pcss_options_subpanel() function. This makes it possible for unauthenticated attackers to update settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Bunnys Print Css

CVE-2025-5925

MEDIUM CVSS 4.3 2025-06-10
Threat Entry Updated 2025-06-12

CVE-2025-4601 - WordPress component

The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to the theme not properly restricting user roles that can be updated as part of the inspiry_update_profile() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to set their role to that of an administrator. The vulnerability was partially patched in version 4.4.0, and fully patched in version 4.4.1.

UNKNOWN WordPress component

CVE-2025-4601

HIGH CVSS 8.8 2025-06-10
Threat Entry Updated 2025-06-12

CVE-2025-31396 - Allows Object Injection Theme

Deserialization of Untrusted Data vulnerability in themeton FLAP - Business WordPress Theme allows Object Injection. This issue affects FLAP - Business WordPress Theme: from n/a through 1.5.

THEME Allows Object Injection

CVE-2025-31396

CRITICAL CVSS 9.8 2025-06-09
Threat Entry Updated 2025-06-12

CVE-2025-28945 - Allows Php Local File Inclusion Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Valen - Sport, Fashion WooCommerce WordPress Theme allows PHP Local File Inclusion. This issue affects Valen - Sport, Fashion WooCommerce WordPress Theme: from n/a through 2.4.

THEME Allows Php Local File Inclusion

CVE-2025-28945

HIGH CVSS 8.1 2025-06-09
Scroll to top