6.4

CVSS3.1

CVE-2025-13738 - Easy Table of Contents <= 2.0.78 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` shortcode in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 8, 2026, 5 p.m.

4.3

CVSS3.1

CVE-2025-13438 - Page Title, Description & Open Graph Updater <= 1.02 - Cross-Site Request Forgery to Arbitrary Page…

The Page Title, Description & Open Graph Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.02. This is due to missing nonce validation on multiple AJAX actions including dieno_update_page_title. This makes it possible for unauthenticate…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 8, 2026, 4:59 p.m.

6.4

CVSS3.1

CVE-2026-0556 - XO Event Calendar <= 3.2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'xo_even…

The XO Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xo_event_field' shortcode in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 8, 2026, 4:59 p.m.

4.4

CVSS3.1

CVE-2026-1047 - salavat counter Plugin <= 0.9.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'i…

The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' parameter in all versions up to, and including, 0.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-l…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 8, 2026, 4:58 p.m.

5.3

CVSS3.1

CVE-2025-13842 - Breadcrumb NavXT <= 7.5.0 - Missing Authorization to Sensitive Information Exposure

The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions up to and including 7.5.0. This is due to the Gutenberg block renderer trusting the $_REQUEST['post_id'] parameter without verification in the includes/blocks/build/breadcrumb-tra…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 8, 2026, 4:57 p.m.

5.3

CVSS3.1

CVE-2025-13864 - Breeze – WordPress Cache Plugin <= 2.2.21 - Missing Authorization to Cache Deletion

The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up to, and including, 2.2.21. This is due to the REST API endpoint `/wp-json/breeze/v1/clear-all-cache` being registered with `permission_callback => '__return_true'` and authentica…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 8, 2026, 4:54 p.m.

6.4

CVSS3.1

CVE-2025-13617 - Apollo13 Framework Extension <= 1.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_link’ parameter in all versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contr…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 8, 2026, 4:54 p.m.

8.8

CVSS3.1

CVE-2025-4521 - IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privi…

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_profile() function in versions 2.1.5 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-leve…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: Feb. 19, 2026, 5:37 p.m.

4.4

CVSS3.1

CVE-2026-2282 - Slidorion <= 1.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Slidorion Setti…

The Slidorion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and abo…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 8, 2026, 4:52 p.m.

7.2

CVSS3.1

CVE-2025-12975 - CTX Feed – WooCommerce Product Feed Manager <= 6.6.11 - Missing Authorization to Authenticated (Sho…

The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated atta…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 8, 2026, 4:52 p.m.
Total resulsts: 344009
Page 1059 of 34,401
« previous page » next page
Filters