Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,886
Critical1,345
High4,572
Medium12,707
Reset
Showing 8981-9000 of 18886 records
Threat Entry Updated 2025-04-29

CVE-2025-3868 - Admin Bookmarks Plugin

The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Admin Bookmarks

CVE-2025-3868

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3867 - Ajax Comment Form Cst Plugin

The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation via the 'acform_cst_settings' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ajax Comment Form Cst

CVE-2025-3867

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3866 - Add Google Plus One Social Share Button Plugin

The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the google-plus-one-share-button page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Add Google Plus One Social Share Button

CVE-2025-3866

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-2238 - Vikinger Theme

The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restrictions in the 'vikinger_user_meta_update_ajax' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator-level.

THEME Vikinger

CVE-2025-2238

HIGH CVSS 8.8 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3743 - Upsell Order Bump Offer For Woocommerce Plugin

The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the 'add_offer_in_cart' function. This makes it possible for unauthenticated attackers to arbitrarily update the product associated with any order bump, and arbitrarily update the discount applied to any order bump item, when adding it to the cart.

PLUGIN Upsell Order Bump Offer For Woocommerce

CVE-2025-3743

MEDIUM CVSS 5.3 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3923 - Prevent Direct Access Plugin

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'generate_unique_string' due to insufficient randomness of the generated file name. This makes it possible for unauthenticated attackers to extract sensitive data including files protected by the plugin if the attacker can determine the file name.

PLUGIN Prevent Direct Access

CVE-2025-3923

MEDIUM CVSS 5.3 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3861 - Prevent Direct Access Plugin

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability check on the 'pda_lite_custom_permission_check' function in versions 2.8.6 to 2.8.8.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to access and change the protection status of media.

PLUGIN Prevent Direct Access

CVE-2025-3861

MEDIUM CVSS 5.4 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-2580 - Bit Form Plugin

The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Bit Form

CVE-2025-2580

MEDIUM CVSS 4.9 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-0671 - Icegram Express Plugin

The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Icegram Express

CVE-2025-0671

MEDIUM CVSS 6.1 2025-04-25
Threat Entry Updated 2025-11-26

CVE-2025-3775 - Shoplentor Plugin

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application, and can be used to query and modify information from internal services.

PLUGIN Shoplentor

CVE-2025-3775

MEDIUM CVSS 6.5 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3752 - Accessible Html5 Media Player Plugin

The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘preload’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Accessible Html5 Media Player

CVE-2025-3752

MEDIUM CVSS 6.4 2025-04-25
Threat Entry Updated 2025-04-29

CVE-2025-3749 - Wt Display Breeze Plugin

The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wt Display Breeze

CVE-2025-3749

MEDIUM CVSS 6.4 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-1294 - Eform Wordpress Form Builder Plugin

The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.18.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Eform Wordpress Form Builder

CVE-2025-1294

HIGH CVSS 7.2 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-46533 - Landing pages and Domain aliases for WordPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdrift.no Landing pages and Domain aliases for WordPress allows Stored XSS. This issue affects Landing pages and Domain aliases for WordPress: from n/a through 0.8.

PLUGIN Landing pages and Domain aliases for WordPress

CVE-2025-46533

MEDIUM CVSS 5.9 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-3832 - Fusedesk Plugin

The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Fusedesk

CVE-2025-3832

MEDIUM CVSS 6.4 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-3793 - Buddy Press Force Password Change Plugin

The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with subscriber-level access and above and under certain prerequisites, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their accounts.

PLUGIN Buddy Press Force Password Change

CVE-2025-3793

MEDIUM CVSS 4.2 2025-04-24
Threat Entry Updated 2025-08-12

CVE-2025-3604 - Flynax Bridge Plugin

The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

PLUGIN Flynax Bridge

CVE-2025-3604

CRITICAL CVSS 9.8 2025-04-24
Threat Entry Updated 2025-08-12

CVE-2025-3603 - Flynax Bridge Plugin

The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Flynax Bridge

CVE-2025-3603

CRITICAL CVSS 9.8 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-3607 - Frontend Login And Registration Blocks Plugin

The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.7. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Frontend Login And Registration Blocks

CVE-2025-3607

HIGH CVSS 8.8 2025-04-24
Threat Entry Updated 2025-04-29

CVE-2025-3776 - Verification Sms Targetsms Plugin

The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targetvr_ajax_handler' function. This is due to a lack of validation on the type of function that can be called. This makes it possible for unauthenticated attackers to execute any callable function on the site, such as phpinfo().

PLUGIN Verification Sms Targetsms

CVE-2025-3776

HIGH CVSS 8.3 2025-04-24
Scroll to top