4.3

CVSS3.1

CVE-2025-11773 - Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.6 - Missing Auth…

The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saveDeployedContract' function in all versions up to, and including, 2.4.6. This makes it possible for au…

📅 Published: Nov. 21, 2025, 7:31 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:56 p.m.

6.4

CVSS3.1

CVE-2025-11763 - Display Pages Shortcode <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Display Pages Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column_count' parameter in the [display-pages] shortcode in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping. This makes it possible for a…

📅 Published: Nov. 21, 2025, 7:31 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:56 p.m.

6.4

CVSS3.1

CVE-2025-13135 - HotelRunner Booking Widget <= 5.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The HotelRunner Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hotelrunner' shortcode in all versions up to, and including, 5.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au…

📅 Published: Nov. 21, 2025, 7:31 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:56 p.m.

6.4

CVSS3.1

CVE-2025-11764 - Shortcodes Bootstrap <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Shortcodes Bootstrap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in the [notification] shortcode in all versions up to, and including, 1.1. This is due to missing input sanitization and output escaping. This makes it possible for authenticated atta…

📅 Published: Nov. 21, 2025, 7:31 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:56 p.m.

6.5

CVSS3.1

CVE-2025-10938 - UiPress lite <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information…

The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with subscriber-level acce…

📅 Published: Nov. 21, 2025, 7:31 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:56 p.m.

5.3

CVSS3.1

CVE-2025-11771 - Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.6 - Missing Auth…

The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'createSaleRecord' function in all versions up to, and including, 2.…

📅 Published: Nov. 21, 2025, 7:31 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:56 p.m.

6.4

CVSS3.1

CVE-2025-11003 - UiPress lite <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scr…

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up to, and including, 3.5.08. This makes it possible for authentic…

📅 Published: Nov. 21, 2025, 7:31 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:56 p.m.

6.4

CVSS3.1

CVE-2025-11799 - Affiliate AI Lite <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Affiliate AI Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'asin' shortcode attribute in the affiai_img shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenti…

📅 Published: Nov. 21, 2025, 7:31 a.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

9.8

CVSS3.1

CVE-2025-11456 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the eh_crm_new_ticket_post() function in all versions up to, and including, 3.3.1. This makes it possible for unauthenticated attackers to uplo…

📅 Published: Nov. 21, 2025, 7:31 a.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

5.4

CVSS3.1

CVE-2025-12881 - Return Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authentic…

The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the wps_rma_fetch_order_msgs() due to missing validation on a user controlled key. This makes it possible for authenticated attackers…

📅 Published: Nov. 21, 2025, 7:31 a.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.
Total resulsts: 319168
Page 16 of 31,917
« previous page » next page
Filters