CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2024-13803

Description: The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-marker’ parameter in all versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS: MEDIUM (6.4)

EPSS Score: 0.03%

Source: CVE
February 26th, 2025 (4 months ago)

CVE-2024-12434

Description: The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including restricted content.

CVSS: MEDIUM (5.3)

EPSS Score: 0.04%

Source: CVE
February 26th, 2025 (4 months ago)

CVE-2025-27000

Description: Missing Authorization vulnerability in George Pattichis Simple Photo Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Photo Feed: from n/a through 1.4.0.

CVSS: MEDIUM (5.4)

EPSS Score: 0.04%

Source: CVE
February 25th, 2025 (4 months ago)

CVE-2025-26995

Description: Missing Authorization vulnerability in Anton Vanyukov Market Exporter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Market Exporter: from n/a through 2.0.21.

CVSS: MEDIUM (5.4)

EPSS Score: 0.04%

Source: CVE
February 25th, 2025 (4 months ago)

CVE-2025-26983

Description: Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Recipe Card Blocks for Gutenberg & Elementor: from n/a through 3.4.3.

CVSS: MEDIUM (4.3)

EPSS Score: 0.03%

Source: CVE
February 25th, 2025 (4 months ago)

CVE-2025-26980

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wired Impact Wired Impact Volunteer Management allows Stored XSS. This issue affects Wired Impact Volunteer Management: from n/a through 2.5.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
February 25th, 2025 (4 months ago)

CVE-2025-26975

Description: Missing Authorization vulnerability in WP Chill Strong Testimonials allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Strong Testimonials: from n/a through 3.2.3.

CVSS: MEDIUM (5.3)

EPSS Score: 0.04%

Source: CVE
February 25th, 2025 (4 months ago)

CVE-2025-26965

Description: Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Amelia: from n/a through 1.2.16.

CVSS: MEDIUM (5.3)

EPSS Score: 0.04%

SSVC Exploitation: none

Source: CVE
February 25th, 2025 (4 months ago)

CVE-2025-26963

Description: Cross-Site Request Forgery (CSRF) vulnerability in flowdee ClickWhale allows Cross Site Request Forgery. This issue affects ClickWhale: from n/a through 2.4.3.

CVSS: MEDIUM (5.4)

EPSS Score: 0.02%

Source: CVE
February 25th, 2025 (4 months ago)

CVE-2025-26962

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Easy Contact Form Lite allows Stored XSS. This issue affects Easy Contact Form Lite : from n/a through 1.1.25.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
February 25th, 2025 (4 months ago)