8.6
CVE-2025-10897 - WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read
The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.
8.8
CVE-2025-7846 - WordPress User Extra Fields <= 16.7 - Authenticated (Subscriber+) Arbitrary File Deletion via save_β¦
The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with Subscriber-level access and aboveβ¦
9.8
CVE-2025-8489 - King Addons for Elementor β Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 β¦
The King Addons for Elementor β Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possiblβ¦
9.8
CVE-2025-5397 - Jobmonster - Job Board WordPress Theme <= 4.8.1 - Authentication Bypass
The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() function not properly verifying a user's identity prior to successfully authenticating them This makes it possible for unauthenticated attackeβ¦
5.3
CVE-2025-11191 - RealPress < 1.1.0 - Unauthenticated Content Creation/Email Sending via REST
The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.
8.6
CVE-2025-54763 -
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of the product may execute an arbitrary OS command.
6.9
CVE-2025-58152 -
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication.
6.4
CVE-2025-11806 - Qzzr Shortcode Plugin <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortβ¦
The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping on the 'quiz' attribute. This makes it possible for authenticated attackers, β¦
4.3
CVE-2025-11975 - FuseWP β WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, Actβ¦
The FuseWP β WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_changes() function in all versions up to, and including, 1.1β¦
0.0
CVE-2025-12542 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.