plugin

Bluet Keywords Tooltip Generator Vulnerabilities

12 known security issues reported for the Bluet Keywords Tooltip Generator WordPress plugin. Most recent disclosed Oct 27, 2025.

4 medium

Running Bluet Keywords Tooltip Generator on your site? Check whether your installed version is affected.

Scan your site free

Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] <= 5.5.9 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jamel.Z Tooltipy bluet-keywords-tooltip-generator allows Stored XSS.This issue affects Tooltipy: from n/a through <= 5.5.9.

Affected:
up to 5.5.9
Fix:
No patched version reported
Disclosed:
Oct 27, 2025

CVE-2025-62917 on NVD →

Tooltipy <= 5.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Tooltipy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
6.4
Affected:
up to 5.5.9
Fix:
No patched version reported
Disclosed:
Oct 3, 2025

CVE-2025-62917 on NVD →

Tooltipy <= 5.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Tooltipy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
6.4
Affected:
up to 5.5.6
Fixed in:
5.5.9
Disclosed:
Sep 3, 2025

CVE-2025-58614 on NVD →

Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.5.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jamel.Z Tooltipy allows Stored XSS. This issue affects Tooltipy: from n/a through 5.5.6.

Affected:
up to 5.5.9
Fixed in:
5.5.9
Disclosed:
Sep 3, 2025

CVE-2025-58614 on NVD →

Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1

unknown

[en] Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybody to duplicate posts. This attack appear to be exploitable via Admin must follow a link. This vulnerability appears to have been fixed in 5.1.

Affected:
up to 5.1
Fixed in:
5.1
Disclosed:
Jun 26, 2018

CVE-2018-1000505 on NVD →

Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1

unknown

[en] Tooltipy Tooltipy (tooltips for WP) version 5 contains a Cross Site Scripting (XSS) vulnerability in Glossary shortcode that can result in could allow anybody to do almost anything an admin can. This attack appear to be exploitable via Admin must follow a link. This vulnerability appears to have been fixed in 5.1.

Affected:
up to 5.1
Fixed in:
5.1
Disclosed:
Jun 26, 2018

CVE-2018-1000512 on NVD →

Tooltipy < 5.1 - Cross-Site Request Forgery

medium

The Tooltipy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on the post_type function. This makes it possible for unauthenticated attackers to caused a Deniel of Service of the database via a forged request gra...

CVSS:
6.5
Affected:
up to 5.1
Fixed in:
5.1
Disclosed:
Jun 20, 2018

CVE-2018-1000505 on NVD →

Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1

unknown

Cross-Site Request Forgery (CSRF) vulnerability found in WordPress Tooltipy (tooltips for WP) plugin (versions <= 5.0).

Affected:
up to 5.1
Fixed in:
5.1
Disclosed:
Jun 20, 2018

Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1

unknown

Unauthenticated Cross-Site Scripting (XSS) vulnerability found in WordPress Tooltipy (tooltips for WP) plugin (versions <= 5.0).

Affected:
up to 5.1
Fixed in:
5.1
Disclosed:
Jun 20, 2018

Tooltipy (tooltips for WP) <= 5.0 - Reflected Cross-Site Scripting

medium

The Tooltipy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the cat parameter in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
6.1
Affected:
up to 5.1
Fixed in:
5.1
Disclosed:
Jun 12, 2018

CVE-2018-1000512 on NVD →

Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1

unknown

The Tooltipy (tooltips for WP) WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.

Affected:
up to 5.1
Fixed in:
5.1

Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator] < 5.1

unknown

The Tooltipy (tooltips for WP) WordPress plugin was affected by an Unauthenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 5.1
Fixed in:
5.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database