Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-2544

Description: The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS: MEDIUM (6.4)

EPSS Score: 0.04%

Source: CVE
April 5th, 2025 (18 days ago)

CVE-2025-0810

Description: The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.5. This is due to missing or incorrect nonce validation on the addNewButtons() function. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS: HIGH (7.5)

EPSS Score: 0.02%

Source: CVE
April 5th, 2025 (18 days ago)

CVE-2024-13604

Description: The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.4 via the 'kbs' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/kbs directory which can contain file attachments included in support tickets. The vulnerability was partially patched in version 1.7.3.2.

CVSS: HIGH (7.5)

EPSS Score: 0.05%

Source: CVE
April 5th, 2025 (18 days ago)

CVE-2025-2889

Description: The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS: MEDIUM (6.4)

EPSS Score: 0.03%

Source: CVE
April 5th, 2025 (18 days ago)

CVE-2025-32280

Description: Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager allows Cross Site Request Forgery. This issue affects WP Project Manager: from n/a through 2.6.22.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 4th, 2025 (18 days ago)

CVE-2025-32278

Description: Cross-Site Request Forgery (CSRF) vulnerability in wprio Table Block by RioVizual allows Cross Site Request Forgery. This issue affects Table Block by RioVizual: from n/a through 2.1.7.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 4th, 2025 (18 days ago)

CVE-2025-32277

Description: Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 3.8211.

CVSS: MEDIUM (4.3)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (18 days ago)

CVE-2025-32276

Description: Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z allows Cross Site Request Forgery. This issue affects Administrator Z: from n/a through 2025.03.04.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 4th, 2025 (18 days ago)

CVE-2025-32274

Description: Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB allows Cross Site Request Forgery. This issue affects WP w3all phpBB: from n/a through 2.9.2.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 4th, 2025 (18 days ago)

CVE-2025-32273

Description: Cross-Site Request Forgery (CSRF) vulnerability in freetobook Freetobook Responsive Widget allows Cross Site Request Forgery. This issue affects Freetobook Responsive Widget: from n/a through 1.1.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 4th, 2025 (18 days ago)