Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] <= 5.5.9 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jamel.Z Tooltipy bluet-keywords-tooltip-generator allows Stored XSS.This issue affects Tooltipy: from n/a through <= 5.5.9.
- Affected:
- up to 5.5.9
- Fix:
- No patched version reported
- Disclosed:
- Oct 27, 2025
CVE-2025-62917 on NVD →
Tooltipy <= 5.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Tooltipy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 5.5.9
- Fix:
- No patched version reported
- Disclosed:
- Oct 3, 2025
CVE-2025-62917 on NVD →
Tooltipy <= 5.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Tooltipy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 5.5.6
- Fixed in:
- 5.5.9
- Disclosed:
- Sep 3, 2025
CVE-2025-58614 on NVD →
Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.5.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jamel.Z Tooltipy allows Stored XSS. This issue affects Tooltipy: from n/a through 5.5.6.
- Affected:
- up to 5.5.9
- Fixed in:
- 5.5.9
- Disclosed:
- Sep 3, 2025
CVE-2025-58614 on NVD →
Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1
unknown
[en] Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybody to duplicate posts. This attack appear to be exploitable via Admin must follow a link. This vulnerability appears to have been fixed in 5.1.
- Affected:
- up to 5.1
- Fixed in:
- 5.1
- Disclosed:
- Jun 26, 2018
CVE-2018-1000505 on NVD →
Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1
unknown
[en] Tooltipy Tooltipy (tooltips for WP) version 5 contains a Cross Site Scripting (XSS) vulnerability in Glossary shortcode that can result in could allow anybody to do almost anything an admin can. This attack appear to be exploitable via Admin must follow a link. This vulnerability appears to have been fixed in 5.1.
- Affected:
- up to 5.1
- Fixed in:
- 5.1
- Disclosed:
- Jun 26, 2018
CVE-2018-1000512 on NVD →
Tooltipy < 5.1 - Cross-Site Request Forgery
medium
The Tooltipy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on the post_type function. This makes it possible for unauthenticated attackers to caused a Deniel of Service of the database via a forged request gra...
- CVSS:
- 6.5
- Affected:
- up to 5.1
- Fixed in:
- 5.1
- Disclosed:
- Jun 20, 2018
CVE-2018-1000505 on NVD →
Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1
unknown
Cross-Site Request Forgery (CSRF) vulnerability found in WordPress Tooltipy (tooltips for WP) plugin (versions <= 5.0).
- Affected:
- up to 5.1
- Fixed in:
- 5.1
- Disclosed:
- Jun 20, 2018
Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1
unknown
Unauthenticated Cross-Site Scripting (XSS) vulnerability found in WordPress Tooltipy (tooltips for WP) plugin (versions <= 5.0).
- Affected:
- up to 5.1
- Fixed in:
- 5.1
- Disclosed:
- Jun 20, 2018
Tooltipy (tooltips for WP) <= 5.0 - Reflected Cross-Site Scripting
medium
The Tooltipy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the cat parameter in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 5.1
- Fixed in:
- 5.1
- Disclosed:
- Jun 12, 2018
CVE-2018-1000512 on NVD →
Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1
unknown
The Tooltipy (tooltips for WP) WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.
- Affected:
- up to 5.1
- Fixed in:
- 5.1
Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1
unknown
The Tooltipy (tooltips for WP) WordPress plugin was affected by an Unauthenticated Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 5.1
- Fixed in:
- 5.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database