6.4

CVSS3.1

CVE-2025-12117 - Renden <= 1.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title

The Renden theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inje…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 21, 2026, 12:15 a.m.

5.3

CVSS3.1

CVE-2025-13113 - Web Accessibility by accessiBe <= 2.11 - Unauthenticated Sensitive Information Exposure

The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11. This is due to the `accessibe_render_js_in_footer()` function logging the complete plugin options array to the browser console on public pages, without…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

8.8

CVSS3.1

CVE-2025-12845 - Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent 0.5.4 - 1.2.1 - Missi…

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access of data that leads to privilege escalation due to a missing capability check on the get_table_data() function in versions 0.5.4 to 1.2.1. This makes it possibl…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-12884 - Advanced Ads – Ad Manager & AdSense <= 2.0.14 - Missing Authorization to Authenticated (Subscriber+…

The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.14. This is due to the plugin not properly verifying that a user is authorized to perform an action in the `placement_update_item()` function. This makes it possi…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 21, 2026, 12:15 a.m.

8.8

CVSS3.1

CVE-2025-12821 - NewsBlogger <= 0.2.5.6 - 0.2.6.1 - Cross-Site Request Forgery to Arbitrary Plugin Installation

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary f…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-12116 - Drift <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title

The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to injec…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 22, 2026, noon

9.8

CVSS3.1

CVE-2025-12882 - Clasifico Listing <= 2.0 - Unauthenticated Privilege Escalation

The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin allowing users who are registering new accounts to set their own role by supplying the 'listing_user_role' parameter. This makes it possible for unauthen…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

7.5

CVSS3.1

CVE-2025-12707 - Library Management System <= 3.2.1 - Unauthenticated SQL Injection

The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

5.3

CVSS3.1

CVE-2025-13079 - Popup Builder - Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Aut…

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.2. This is due to the plugin generating predictable unsubscribe tokens using deterministic data. This makes it possibl…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

6.4

CVSS3.1

CVE-2025-12375 - Printful Integration for WooCommerce <= 2.2.11 - Authenticated (Contributor+) Server-Side Request F…

The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.11 via the advanced size chart REST API endpoint. This is due to insufficient validation of user-supplied URLs before passing them to the download_url…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 22, 2026, noon
Total resulsts: 349182
Page 1577 of 34,919
« previous page » next page
Filters