7.5

CVSS3.1

CVE-2025-6814 - Booking X 1.0 - 1.1.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure v…

The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_now() function in versions 1.0 to 1.1.2. This makes it possible for unauthenticated attackers to download all plugin data, including user accounts, user meta, and PayPal c…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: July 4, 2025, 3:15 a.m.

8.8

CVSS3.1

CVE-2025-5953 - WP Human Resource Management 2.0.0 - 2.2.17 - Missing Authorization to Authenticated (Employee+) Pr…

The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee() and update_empoyee() functions in versions 2.0.0 through 2.2.17. The AJAX handler reads the client-supplied $_POST['role'] and, after basic cleaning…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: July 4, 2025, 3:15 a.m.

7.2

CVSS3.1

CVE-2025-6586 - Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwap_plugin_locInstall function in all versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: July 4, 2025, 3:15 a.m.

6.4

CVSS3.1

CVE-2025-6729 - PayMaster for WooCommerce <= 0.4.31 - Authenticated (Subscriber+) Server-Side Request Forgery

The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.4.31 via the 'wp_ajax_paym_status' AJAX action This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to …

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: July 4, 2025, 3:15 a.m.

6.5

CVSS3.1

CVE-2025-5956 - WP Human Resource Management 2.0.0 - 2.2.17 - Missing Authorization to Authenticated (Employee+) Ar…

The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authorization within the ajax_delete_employee() function in versions 2.0.0 through 2.2.17. The plugin’s deletion handler reads the client-supplied $_POST['delete'] array and passes each I…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: July 4, 2025, 3:15 a.m.

8

CVSS3.1

CVE-2025-6238 - AI Engine 2.8.4 - Insecure OAuth Implementation

The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' parameter is missing validation during the authorization flow. This makes it possible for unauthenticated attackers to intercept the authorizati…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: July 4, 2025, 3:15 a.m.

6.1

CVSS3.1

CVE-2025-6041 - yContributors <= 0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The yContributors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect nonce validation on the 'yContributors' page. This makes it possible for unauthenticated attackers to update settings and inject maliciou…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: July 4, 2025, 3:15 a.m.

6.5

CVSS3.1

CVE-2025-6739 - WPQuiz <= 0.4.2 - Authenticated (Contributor+) SQL Injection

The WPQuiz plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'wpquiz' shortcode in all versions up to, and including, 0.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: July 4, 2025, 3:15 a.m.

6.4

CVSS3.1

CVE-2025-7046 - Portfolio for Elementor & Image Gallery | PowerFolio <= 3.2.0 - Authenticated (Contributor+) Stored…

The Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS Attributes of Plugin's widgets in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible …

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: July 4, 2025, 3:15 a.m.

4.3

CVSS3.1

CVE-2025-5933 - RD Contacto <= 1.4 - Cross-Site Request Forgery to Settings Update

The RD Contacto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the rdWappUpdateData() function. This makes it possible for unauthenticated attackers to update plugin settings via a f…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: July 4, 2025, 3:15 a.m.
Total resulsts: 300530
Page 17 of 30,053
« previous page » next page
Filters