4.3

CVSS3.1

CVE-2025-14342 - SEO Plugin by Squirrly SEO <= 12.4.14 - Missing Authorization to Authenticated (Subscriber+) Cloud …

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sq_ajax_uninstall function in all versions up to, and including, 12.4.14. This makes it possible for authenticated attackers, with Subscriber-level access …

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

6.4

CVSS3.1

CVE-2026-0549 - Groups <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'groups_group_info'…

The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 15, 2026, 8:30 p.m.

6.4

CVSS3.1

CVE-2025-13738 - Easy Table of Contents <= 2.0.78 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` shortcode in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 11:45 p.m.

4.3

CVSS3.1

CVE-2025-13438 - Page Title, Description & Open Graph Updater <= 1.02 - Cross-Site Request Forgery to Arbitrary Page…

The Page Title, Description & Open Graph Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.02. This is due to missing nonce validation on multiple AJAX actions including dieno_update_page_title. This makes it possible for unauthenticate…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

6.4

CVSS3.1

CVE-2026-0556 - XO Event Calendar <= 3.2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'xo_even…

The XO Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xo_event_field' shortcode in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 15, 2026, 6:15 p.m.

4.4

CVSS3.1

CVE-2026-1047 - salavat counter Plugin <= 0.9.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'i…

The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' parameter in all versions up to, and including, 0.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-l…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 16, 2026, 6:45 a.m.

5.3

CVSS3.1

CVE-2025-13842 - Breadcrumb NavXT <= 7.5.0 - Missing Authorization to Sensitive Information Exposure

The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions up to and including 7.5.0. This is due to the Gutenberg block renderer trusting the $_REQUEST['post_id'] parameter without verification in the includes/blocks/build/breadcrumb-tra…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

5.3

CVSS3.1

CVE-2025-13864 - Breeze – WordPress Cache Plugin <= 2.2.21 - Missing Authorization to Cache Deletion

The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up to, and including, 2.2.21. This is due to the REST API endpoint `/wp-json/breeze/v1/clear-all-cache` being registered with `permission_callback => '__return_true'` and authentica…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

6.4

CVSS3.1

CVE-2025-13617 - Apollo13 Framework Extension <= 1.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_link’ parameter in all versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contr…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

8.8

CVSS3.1

CVE-2025-4521 - IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privi…

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_profile() function in versions 2.1.5 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-leve…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 1574 of 34,919
« previous page » next page
Filters