Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-2789

Description: The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_table_rate_shipping_row function in all versions up to, and including, 4.2.19. This makes it possible for unauthenticated attackers to delete Table Rates that can impact the shipping cost calculations.

CVSS: MEDIUM (5.3)

EPSS Score: 0.04%

Source: CVE
April 5th, 2025 (15 days ago)

CVE-2025-1233

Description: The Lafka Plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_options_upload' AJAX function in all versions up to, and including, 7.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the theme option that overrides the site.

CVSS: MEDIUM (4.3)

EPSS Score: 0.03%

Source: CVE
April 5th, 2025 (15 days ago)

CVE-2025-0839

Description: The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS: MEDIUM (6.4)

EPSS Score: 0.03%

Source: CVE
April 5th, 2025 (15 days ago)

CVE-2025-2544

Description: The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS: MEDIUM (6.4)

EPSS Score: 0.04%

Source: CVE
April 5th, 2025 (15 days ago)

CVE-2025-2889

Description: The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS: MEDIUM (6.4)

EPSS Score: 0.03%

Source: CVE
April 5th, 2025 (16 days ago)

CVE-2025-32280

Description: Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager allows Cross Site Request Forgery. This issue affects WP Project Manager: from n/a through 2.6.22.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 4th, 2025 (16 days ago)

CVE-2025-32278

Description: Cross-Site Request Forgery (CSRF) vulnerability in wprio Table Block by RioVizual allows Cross Site Request Forgery. This issue affects Table Block by RioVizual: from n/a through 2.1.7.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 4th, 2025 (16 days ago)

CVE-2025-32277

Description: Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 3.8211.

CVSS: MEDIUM (4.3)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (16 days ago)

CVE-2025-32276

Description: Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z allows Cross Site Request Forgery. This issue affects Administrator Z: from n/a through 2025.03.04.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 4th, 2025 (16 days ago)

CVE-2025-32274

Description: Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB allows Cross Site Request Forgery. This issue affects WP w3all phpBB: from n/a through 2.9.2.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 4th, 2025 (16 days ago)