2.7

CVSS3.1

CVE-2025-14270 - OneClick Chat to Order <= 1.0.9 - Missing Authorization to Authenticated (Editor+) Plugin Settings …

The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action in the wa_order_number_save_number_field function. This makes it possible fo…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 20, 2026, 9 p.m.

9.8

CVSS3.1

CVE-2025-13563 - Lizza LMS Pro <= 1.0.3 - Unauthenticated Privilege Escalation

The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_lms_pro_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attacker…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 12:15 a.m.

6.4

CVSS3.1

CVE-2025-14851 - YaMaps for WordPress <= 0.6.40 - Authenticated (Contributor+) Stored Cross-Site Scripting via Short…

The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `yamap` shortcode parameters in all versions up to, and including, 0.6.40 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 12:15 a.m.

4.4

CVSS3.1

CVE-2026-1044 - Tennis Court Bookings <= 1.2.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via Adm…

The Tennis Court Bookings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permiss…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 15, 2026, 8:30 p.m.

4.3

CVSS3.1

CVE-2025-14427 - Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches <= 21.0.9 - Missing Au…

The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `MfaEmailDisable` action in all versions up to, and including, 21.0.9. This makes it possible for authent…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

4.3

CVSS3.1

CVE-2025-14864 - Virusdie <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) API Key Disclosure

The Virusdie - One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.7. This is due to missing capability checks on the `vd_get_apikey` function which is hooked to `wp_ajax_virusdie_apikey`. This makes it possible f…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 22, 2026, 3:45 a.m.

4.3

CVSS3.1

CVE-2025-13091 - Shopire <= 1.0.57 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install

The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the shopire_admin_install_plugin() function in all versions up to, and including, 1.0.57. This makes it possible for authenticated attackers, with Subscriber-level access and abov…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

8.8

CVSS3.1

CVE-2025-13603 - WP AUDIO GALLERY <= 2.0 - Authenticated (Subscriber+) Arbitrary File Read via .htaccess Manipulation

The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attac…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

4.4

CVSS3.1

CVE-2026-1043 - PostmarkApp Email Integrator <= 2.4 - Authenticated (Administrator+) Stored Cross-Site Scripting vi…

The PostmarkApp Email Integrator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 2.4. This is due to insufficient input sanitization and output escaping on the pma_api_key and pma_sender_address parameters. This makes it po…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 15, 2026, 8:30 p.m.

6.1

CVSS3.1

CVE-2025-14076 - iXML – Google XML sitemap generator <= 0.6 - Reflected Cross-Site Scripting via 'iXML_email' Parame…

The iXML – Google XML sitemap generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'iXML_email' parameter in all versions up to, and including, 0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.
Total resulsts: 349182
Page 1573 of 34,919
« previous page » next page
Filters