5.4

CVSS3.1

CVE-2025-66063 - WordPress WP Google Review Slider plugin <= 17.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Google Review Slider: from n/a through <= 17.4.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 5:15 p.m.

3.7

CVSS3.1

CVE-2025-66062 - WordPress WP YouTube Lyte plugin <= 1.7.28 - Open Redirection vulnerability

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allows Phishing.This issue affects WP YouTube Lyte: from n/a through <= 1.7.28.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 5:15 p.m.

4.3

CVSS3.1

CVE-2025-66061 - WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Cross Site Request Forgery (CSRF) vulnerab…

Cross-Site Request Forgery (CSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Cross Site Request Forgery.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 5:15 p.m.

5.3

CVSS3.1

CVE-2025-66060 - WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 4:16 p.m.

5.3

CVSS3.1

CVE-2025-66059 - WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Retrieve Embedded Sensitive Data.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:15 p.m.

6.3

CVSS3.1

CVE-2025-66057 - WordPress Bold Page Builder plugin <= 5.5.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows DOM-Based XSS.This issue affects Bold Page Builder: from n/a through <= 5.5.2.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:15 p.m.

4.3

CVSS3.1

CVE-2025-66056 - WordPress Uncanny Automator plugin < 6.10.0 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Retrieve Embedded Sensitive Data.This issue affects Uncanny Automator: from n/a through < 6.10.0.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:15 p.m.

7.2

CVSS3.1

CVE-2025-66055 - WordPress Email Subscribers & Newsletters plugin <= 5.9.10 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:15 p.m.

6.5

CVSS3.1

CVE-2025-66053 - WordPress Enfold theme <= 7.1.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold enfold allows Stored XSS.This issue affects Enfold: from n/a through <= 7.1.2.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:15 p.m.

4.3

CVSS3.1

CVE-2025-10039 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.2.9 - Authenticated (Subscriber+) Insecure…

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.9 via the 'eh_crm_ticket_single_view_client' due to missing validation on a user controlled key. This makes it possible for authen…

πŸ“… Published: Nov. 21, 2025, 12:28 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.
Total resulsts: 319167
Page 13 of 31,917
Β« previous page Β» next page
Filters