5.3

CVSS3.1

CVE-2025-12094 - OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) <= 1.2.53 - Unauthenโ€ฆ

The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to IP Header Spoofing in all versions up to, and including, 1.2.53. This is due to the plugin trusting client-controlled forwarded headers (such as CF-Connecting-IP, X-Forwarded-Forโ€ฆ

๐Ÿ“… Published: Oct. 31, 2025, 8:25 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

4.3

CVSS3.1

CVE-2025-12175 - The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Tiโ€ฆ

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to vโ€ฆ

๐Ÿ“… Published: Oct. 31, 2025, 8:25 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

9.8

CVSS3.1

CVE-2025-6520 - SQLi in Abis Technology's BAPSIS

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BAPSIS allows Blind SQL Injection.This issue affects BAPSIS: before 202510271606.

๐Ÿ“… Published: Oct. 31, 2025, 7:44 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

6.8

CVSS3.1

CVE-2025-8385 - Zombify <= 1.7.5 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read

The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is due to insufficient input validation in the zf_get_file_by_url function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read arbitrarโ€ฆ

๐Ÿ“… Published: Oct. 31, 2025, 7:26 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

8.6

CVSS3.1

CVE-2025-10897 - WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.

๐Ÿ“… Published: Oct. 31, 2025, 7:26 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

8.8

CVSS3.1

CVE-2025-7846 - WordPress User Extra Fields <= 16.7 - Authenticated (Subscriber+) Arbitrary File Deletion via save_โ€ฆ

The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with Subscriber-level access and aboveโ€ฆ

๐Ÿ“… Published: Oct. 31, 2025, 6:42 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

9.8

CVSS3.1

CVE-2025-8489 - King Addons for Elementor โ€“ Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 โ€ฆ

The King Addons for Elementor โ€“ Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possiblโ€ฆ

๐Ÿ“… Published: Oct. 31, 2025, 6:42 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

9.8

CVSS3.1

CVE-2025-5397 - Jobmonster - Job Board WordPress Theme <= 4.8.1 - Authentication Bypass

The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() function not properly verifying a user's identity prior to successfully authenticating them This makes it possible for unauthenticated attackeโ€ฆ

๐Ÿ“… Published: Oct. 31, 2025, 6:42 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

5.3

CVSS3.1

CVE-2025-11191 - RealPress < 1.1.0 - Unauthenticated Content Creation/Email Sending via REST

The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.

๐Ÿ“… Published: Oct. 31, 2025, 6 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

8.6

CVSS4.0

CVE-2025-54763 -

FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of the product may execute an arbitrary OS command.

๐Ÿ“… Published: Oct. 31, 2025, 5:55 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.
Total resulsts: 318050
Page 157 of 31,805
ยซ previous page ยป next page
Filters