CVE ID | CVSS | Researchers | Package Name | Version | Title | Severity | Published Date |
---|---|---|---|---|---|---|---|
No CVE | 5.5 | Unknown | Amministrazione Trasparente | * - 9.0 | Amministrazione Trasparente <= 9.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via print_r Function | Medium | 2025-08-30 16:22:25 |
No CVE | 6.4 | Unknown | TablePress – Tables in WordPress made easy | * - 3.2 | TablePress <= 3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_debug Parameter | Medium | 2025-08-29 16:24:26 |
No CVE | 6.4 | Unknown | Ocean Extra | * - 2.4.9 | Ocean Extra <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via oceanwp_library Shortcode | Medium | 2025-08-29 16:24:26 |
No CVE | 4.3 | Unknown | Ultimate Tag Warrior Importer | * - 0.2 | Ultimate Tag Warrior Importer <= 0.2 - Cross-Site Request Forgery | Medium | 2025-08-28 15:44:35 |
No CVE | 6.4 | Unknown | OSM Map Widget for Elementor | * - 1.3.0 | OSM Map Widget for Elementor <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button URL | Medium | 2025-08-28 15:44:06 |
No CVE | 8.1 | Unknown | Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools | * - 7.2.4 | Booster for WooCommerce <= 7.2.4 - Unauthenticated Double Extension Arbitrary File Upload | High | 2025-08-28 00:00:00 |
No CVE | 4.3 | Unknown | LWSCache | * - 2.8.5 | LWSCache <= 2.8.5 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation via lwscache_activatePlugin Function | Medium | 2025-08-28 00:00:00 |
No CVE | 6.4 | Unknown | Dynamic AJAX Product Filters for WooCommerce | * - 1.3.7 | Dynamic AJAX Product Filters for WooCommerce <= 1.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via className Parameter | Medium | 2025-08-27 17:44:32 |
No CVE | 6.4 | Unknown | Dynamic AJAX Product Filters for WooCommerce | * - 1.3.7 | Dynamic AJAX Product Filters for WooCommerce <= 1.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via name Parameter | Medium | 2025-08-27 17:41:28 |
No CVE | 5.3 | Unknown | Ajax Search Lite – Live Search & Filter | * - 4.13.1 | Ajax Search Lite <= 4.13.1 - Missing Authorization to Unauthenticated Basic Information Exposure via ASL_Query in AJAX Search Handler | Medium | 2025-08-27 16:25:29 |
No CVE | 9.8 | Unknown | RingCentral Communications Plugin – FREE | 1.5 - 1.6.8 | RingCentral Communications 1.5 - 1.6.8 - Missing Server‑Side Verification to Authentication Bypass via ringcentral_admin_login_2fa_verify Function | Critical | 2025-08-27 16:25:29 |
No CVE | 6.1 | Unknown | WP ULike Pro | * - 1.9.3 | WP ULike Pro <= 1.9.3 - Unauthenticated Limited Arbitrary File Upload | Medium | 2025-08-27 15:20:47 |
No CVE | 4.9 | Unknown | File Manager, Code Editor, and Backup by Managefy | * - 1.4.8 | File Manager, Code Editor, and Backup by Managefy <= 1.4.8 - Authenticated (Admin+) Path Traversal to Arbitrary File Download | Medium | 2025-08-27 14:40:26 |
No CVE | 4.3 | Unknown | AI Hub - Startup & Technology WordPress Theme | * | LiquidThemes Themes <= Various Versions - Missing Authorization to Authenticated (Subscriber+) All Plugins Deactivated | Medium | 2025-08-27 00:00:00 |
No CVE | 5.4 | Unknown | Pronamic Google Maps | * - 2.4.1 | Pronamic Google Maps <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | Medium | 2025-08-27 00:00:00 |
No CVE | 6.1 | Unknown | Beaver Builder – WordPress Page Builder | * - 2.9.2.1 | Beaver Builder Plugin (Lite Version) <= 2.9.2.1 - Reflected Cross-Site Scripting | Medium | 2025-08-27 00:00:00 |
No CVE | 7.5 | Unknown | Xagio SEO – AI Powered SEO | * - 7.1.0.5 | Xagio SEO <= 7.1.0.5 - Unauthenticated Sensitive Information Exposure via Unprotected Back-Up Files | High | 2025-08-27 00:00:00 |
No CVE | 6.5 | Unknown | Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection | * - 11.58 | Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 11.58 - Insufficient Authorization to Unauthenticated Blocklist Bypass | Medium | 2025-08-27 00:00:00 |
No CVE | 8.8 | Unknown | Video Share VOD – Turnkey Video Site Builder Script | * - 2.7.6 | Video Share VOD – Turnkey Video Site Builder Script <= 2.7.6 - Cross-Site Request Forgery to Command Injection | High | 2025-08-27 00:00:00 |
No CVE | 6.5 | Unknown | Simple Download Monitor | * - 3.9.33 | Simple Download Monitor <= 3.9.33 - Simple Download Monitor <= 3.9.33 – Authenticated (Contributor+) SQL Injection via order parameter in Log Export functionality | Medium | 2025-08-27 00:00:00 |
No CVE | 6.4 | Unknown | Unlimited Elements For Elementor | * - 1.5.148 | Unlimited Elements For Elementor <= 1.5.148 - Authenticated (Contributor+) Stored Cross-Site Scripting | Medium | 2025-08-27 00:00:00 |
No CVE | 6.4 | Unknown | Booking Calendar | * - 10.14.1 | Booking Calendar <= 10.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | Medium | 2025-08-27 00:00:00 |
No CVE | 6.4 | Unknown | UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP | * - 1.2.42 | UsersWP <= 1.2.42 - Authenticated (Contributor+) Stored Cross-Site Scripting | Medium | 2025-08-27 00:00:00 |
No CVE | 6.4 | Unknown | Lazy Load for Videos | * - 2.18.7 | Lazy Load for Videos <= 2.18.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via data-video-title and href Attributes | Medium | 2025-08-26 12:22:01 |
No CVE | 4.4 | Unknown | All-in-One WP Migration and Backup | * - 7.97 | All-in-One WP Migration and Backup <= 7.97 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import | Medium | 2025-08-26 10:28:31 |
A plugin to fetch and display vulnerabilities from the Wordfence Intelligence Vulnerability Database API with advanced search, filtering, and pagination functionality.
== Description ==
The **Wordfence Intelligence API Plugin** allows you to integrate with the Wordfence Intelligence Vulnerability Database and display a list of vulnerabilities on your WordPress site. The plugin supports AJAX-based search, filtering, and pagination to enhance user experience.
**Key Features:**
– Fetch vulnerabilities from the Wordfence Intelligence API.
– Display vulnerabilities in a customizable table with sorting, filtering, and search.
– Responsive design for mobile and desktop users.
– AJAX-powered updates for seamless interaction without page reloads.
– Pagination with range limits and ellipses for a clean UI.
**Shortcode Example:**
Add the following shortcode to any page or post to display the vulnerabilities:
“`html
wfi_vulnerabilities
Contact us today to request a consultation and discover how our expert solutions can help your business thrive.