Search Results

Updated 1h ago
337,123 CVEs tracked 53,223 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,429 researchers
16,593 results for "wordpress plugin" Clear all
CVE-2015-6668 7.5 HIGH 6 PoCs Analysis EPSS 0.84
Wp-jobmanager Job Manager < 0.7.24 - Information Disclosure
The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.
CWE-200 Oct 19, 2017
CVE-2024-13421 9.8 CRITICAL EPSS 0.01
The Real Estate 7 WordPress theme - Privilege Escalation
The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.
CWE-266 Feb 12, 2025
CVE-2025-5394 9.8 CRITICAL EXPLOITED 5 PoCs Analysis NUCLEI EPSS 0.28
Alone - Charity Multipurpose Non-profit WordPress Theme <7.8.3 - RCE
The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution.
CWE-862 Jul 15, 2025
CVE-2025-13680 8.8 HIGH EPSS 0.00
Tiger theme WordPress - Privilege Escalation
The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the plugin allowing a user to update the user role through the $user->set_role() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
CWE-269 Nov 27, 2025
CVE-2017-14723 9.8 CRITICAL EXPLOITED 1 Writeup EPSS 0.10
WordPress <4.8.2 - SQL Injection
Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.
CWE-89 Sep 23, 2017
CVE-2025-13091 4.3 MEDIUM EPSS 0.00
Shopire WordPress Theme <=1.0.57 - Privilege Escalation
The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the shopire_admin_install_plugin() function in all versions up to, and including, 1.0.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the 'fable-extra' plugin.
CWE-15 Feb 19, 2026
CVE-2025-11164 4.3 MEDIUM EPSS 0.00
Mavix Education <1.0 - Privilege Escalation
The Mavix Education theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mavix_education_activate_plugin' AJAX action in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Creativ Demo Importer plugin.
CWE-862 Dec 13, 2025
CVE-2024-6987 4.3 MEDIUM EPSS 0.00
Themebeez Orchid Store < 1.5.7 - Missing Authorization
The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'orchid_store_activate_plugin' function in all versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Addonify Floating Cart For WooCommerce plugin if it is installed.
CWE-862 Aug 08, 2024
CVE-2026-1729 9.8 CRITICAL 2 PoCs Analysis EPSS 0.00
AdForest theme <6.0.12 - Auth Bypass
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.
CWE-306 Feb 12, 2026
CVE-2025-11746 8.8 HIGH EPSS 0.00
XStore <9.5.4 - Code Injection
The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via theet_ajax_required_plugins_popup() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
CWE-22 Oct 15, 2025
CVE-2025-8359 9.8 CRITICAL 2 PoCs Analysis EPSS 0.01
AdForest theme <6.0.9 - Auth Bypass
The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, including administrators, without access to a password.
CWE-288 Sep 06, 2025
CVE-2025-1304 8.8 HIGH 2 PoCs Analysis EPSS 0.02
Spicethemes Newsblogger < 0.2.5.2 - Missing Authorization
The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up to, and including, 0.2.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-862 May 01, 2025
CVE-2024-12281 9.8 CRITICAL EPSS 0.00
Homey theme <2.4.2 - Privilege Escalation
The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the Editor or Shop Manager role.
CWE-269 Mar 05, 2025
CVE-2025-1307 9.8 CRITICAL 2 PoCs Analysis EPSS 0.24
Spicethemes Newscrunch < 1.8.4.1 - Missing Authorization
The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-862 Mar 04, 2025
CVE-2024-12857 9.8 CRITICAL EPSS 0.00
Scriptsbundle Adforest < 5.1.9 - Missing Authentication
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number.
CWE-306 Jan 22, 2025
CVE-2024-11349 9.8 CRITICAL EPSS 0.07
AdForest theme <5.1.6 - Auth Bypass
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the sb_login_user_with_otp_fun() function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.
CWE-288 Dec 21, 2024
CVE-2025-10690 9.8 CRITICAL EPSS 0.00
Goza - Nonprofit Charity WordPress Theme <3.2.2 - RCE
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads due to a missing capability check on the 'beplus_import_pack_install_plugin' function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution.
CWE-862 Sep 19, 2025
CVE-2023-23806 5.9 MEDIUM EPSS 0.00
Wordpress Custom Settings - XSS
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Davinder Singh Custom Settings plugin <= 1.0 versions.
CWE-79 Apr 23, 2023
CVE-2024-8682 5.3 MEDIUM 1 PoC Analysis EPSS 0.00
JNews - WordPress Newspaper Magazine Blog AMP Theme <11.6.6 - Unaut...
The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. This is due to the plugin not properly validate if the user can register option is enabled prior to creating a user though the register_handler() function. This makes it possible for unauthenticated attackers to register as a user even when user registration is disabled.
CWE-862 Mar 05, 2025
CVE-2014-8739 9.8 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.92
jQuery File Upload Plugin <6.4.4 - RCE
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.
CWE-434 Feb 08, 2020