Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2024-1986

Description: The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wc_add_new_product() function in all versions up to, and including, 7.1.7. This makes it possible for customer-level attackers, and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This is only exploitable when the user product upload functionality is enabled.

CVSS: HIGH (8.8)

EPSS Score: 4.32%

SSVC Exploitation: none

Source: CVE
April 16th, 2025 (about 2 months ago)

CVE-2025-39592

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Unlock Lite allows PHP Local File Inclusion. This issue affects Subscribe to Unlock Lite: from n/a through 1.3.0.

CVSS: HIGH (7.5)

EPSS Score: 0.13%

Source: CVE
April 16th, 2025 (about 2 months ago)

CVE-2025-39584

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter Eventin allows PHP Local File Inclusion. This issue affects Eventin: from n/a through 4.0.25.

CVSS: HIGH (7.5)

EPSS Score: 0.13%

Source: CVE
April 16th, 2025 (about 2 months ago)

CVE-2025-39570

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Lomu WPCOM Member allows PHP Local File Inclusion. This issue affects WPCOM Member: from n/a through 1.7.7.

CVSS: HIGH (8.8)

EPSS Score: 0.13%

Source: CVE
April 16th, 2025 (about 2 months ago)

CVE-2025-39566

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Hostel allows Blind SQL Injection. This issue affects Hostel: from n/a through 1.1.5.6.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
April 16th, 2025 (about 2 months ago)

CVE-2025-39548

Description: Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban allows Stored XSS. This issue affects Right Click Disable OR Ban: from n/a through 1.1.17.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
April 16th, 2025 (about 2 months ago)

CVE-2025-39547

Description: Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Internal Link Optimiser allows Stored XSS. This issue affects Internal Link Optimiser: from n/a through 5.1.3.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
April 16th, 2025 (about 2 months ago)

CVE-2025-39544

Description: Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi WP Tools allows Path Traversal. This issue affects WP Tools: from n/a through 5.18.

CVSS: HIGH (7.4)

EPSS Score: 0.02%

Source: CVE
April 16th, 2025 (about 2 months ago)

CVE-2025-39530

Description: Cross-Site Request Forgery (CSRF) vulnerability in dsky Site Search 360 allows Stored XSS. This issue affects Site Search 360: from n/a through 2.1.7.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
April 16th, 2025 (about 2 months ago)

CVE-2025-39518

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedefiningTheWeb BMA Lite allows SQL Injection. This issue affects BMA Lite: from n/a through 1.4.2.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
April 16th, 2025 (about 2 months ago)