Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,886
Critical1,345
High4,572
Medium12,707
Reset
Showing 8581-8600 of 18886 records
Threat Entry Updated 2025-05-21

CVE-2025-4322 - Motors Theme

The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user passwords, including those of administrators, and leverage that to gain access to their account.

THEME Motors

CVE-2025-4322

CRITICAL CVSS 9.8 2025-05-20
Threat Entry Updated 2025-06-12

CVE-2025-2929 - Order Delivery Date Plugin

The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Order Delivery Date

CVE-2025-2929

HIGH CVSS 7.1 2025-05-20
Threat Entry Updated 2025-05-21

CVE-2025-39372 - WordPress Events Calendar Registration & Tickets Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPress Events Calendar Registration & Tickets allows Reflected XSS.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through 2.6.0.

PLUGIN WordPress Events Calendar Registration & Tickets

CVE-2025-39372

HIGH CVSS 7.1 2025-05-19
Threat Entry Updated 2026-01-22

CVE-2025-39352 - Grand Restaurant Plugin

Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-39352

HIGH CVSS 8.2 2025-05-19
Threat Entry Updated 2025-05-29

CVE-2025-39348 - Grand Restaurant Plugin

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant WordPress allows Object Injection.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-39348

CRITICAL CVSS 9.8 2025-05-19
Threat Entry Updated 2025-06-09

CVE-2025-32926 - Grand Restaurant Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaurant WordPress allows Path Traversal.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-32926

CRITICAL CVSS 9.8 2025-05-19
Threat Entry Updated 2025-05-21

CVE-2025-39411 - Plugins Whatsapp Click To Chat

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Indie_Plugins WhatsApp Click to Chat Plugin for WordPress.This issue affects WhatsApp Click to Chat Plugin for WordPress: from n/a through 2.2.12.

PLUGIN Plugins Whatsapp Click To Chat

CVE-2025-39411

HIGH CVSS 7.5 2025-05-19
Threat Entry Updated 2025-05-21

CVE-2025-39409 - WordPress Video Robot - The Ultimate Video Importer Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pressaholic WordPress Video Robot - The Ultimate Video Importer.This issue affects WordPress Video Robot - The Ultimate Video Importer: from n/a through 1.20.0.

PLUGIN WordPress Video Robot - The Ultimate Video Importer

CVE-2025-39409

HIGH CVSS 7.1 2025-05-19
Threat Entry Updated 2025-05-21

CVE-2025-47582 - WordPress Core

Deserialization of Untrusted Data vulnerability in QuantumCloud WPBot Pro Wordpress Chatbot allows Object Injection.This issue affects WPBot Pro Wordpress Chatbot: from n/a through 12.7.0.

CORE WordPress Core

CVE-2025-47582

CRITICAL CVSS 9.8 2025-05-19
Threat Entry Updated 2025-05-21

CVE-2025-47576 - Vulnerability In Bringthepixel Bimber Viral Magazine Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bringthepixel Bimber - Viral Magazine WordPress Theme.This issue affects Bimber - Viral Magazine WordPress Theme: from n/a through 9.2.5.

THEME Vulnerability In Bringthepixel Bimber Viral Magazine

CVE-2025-47576

HIGH CVSS 8.8 2025-05-19
Threat Entry Updated 2025-05-21

CVE-2025-46262 - Mad Mimi for WordPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz Mad Mimi for WordPress allows Stored XSS.This issue affects Mad Mimi for WordPress: from n/a through 1.5.1.

PLUGIN Mad Mimi for WordPress

CVE-2025-46262

MEDIUM CVSS 6.5 2025-05-19
Threat Entry Updated 2026-01-22

CVE-2025-39353 - Grand Restaurant Plugin

Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-39353

MEDIUM CVSS 5.3 2025-05-19
Threat Entry Updated 2026-01-22

CVE-2025-39351 - Grand Restaurant Plugin

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant WordPress allows Cross Site Request Forgery.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

PLUGIN Grand Restaurant

CVE-2025-39351

MEDIUM CVSS 4.3 2025-05-19
Threat Entry Updated 2026-01-09

CVE-2025-2561 - Ninja Forms Plugin

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Ninja Forms

CVE-2025-2561

MEDIUM CVSS 4.8 2025-05-19
Threat Entry Updated 2026-01-09

CVE-2025-2560 - Ninja Forms Plugin

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Ninja Forms

CVE-2025-2560

MEDIUM CVSS 4.8 2025-05-19
Threat Entry Updated 2026-01-09

CVE-2025-2524 - Ninja Forms Plugin

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Ninja Forms

CVE-2025-2524

MEDIUM CVSS 4.8 2025-05-19
Threat Entry Updated 2026-01-09

CVE-2025-1627 - Qi Blocks Plugin

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Qi Blocks

CVE-2025-1627

MEDIUM CVSS 5.4 2025-05-19
Threat Entry Updated 2026-01-09

CVE-2025-1626 - Qi Blocks Plugin

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Qi Blocks

CVE-2025-1626

MEDIUM CVSS 5.4 2025-05-19
Scroll to top