6.1

CVSS3.1

CVE-2025-12410 - SH Contextual Help <= 3.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation in the sh_contextual_help_dashboard_widget() function. This makes it possible for unauthenticated attackers to up…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 9:01 p.m.

6.5

CVSS3.1

CVE-2025-11758 - All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0.3 - Missing Author…

The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization check in all versions up to, and including, 2.0.3. This is due to the plugin exposing admin-level AJAX actions to unauthenticated users via wp_ajax_nopriv_ hooks, while relying o…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 9 p.m.

5.4

CVSS3.1

CVE-2025-12413 - Social Media WPCF7 Stop Words <= 1.1.3 - Cross-Site Request Forgery to Settings Update

The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the smWpCfSwOptions() function. This makes it possible for unauthenticated attackers to update the …

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 9 p.m.

5.3

CVSS3.1

CVE-2025-12350 - DominoKit <= 1.1.0 - Missing Authorization to Unauthenticated Settings Update

The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admin_action AJAX endpoint in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update plugin settings.

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 8:59 p.m.

4.4

CVSS3.1

CVE-2025-12393 - Free Quotation <= 3.1.6 - Authenticated (Admin+) Stored Cross-Site Scripting

The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions an…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 8:58 p.m.

6.1

CVSS3.1

CVE-2025-12416 - Pagerank Tools <= 1.1.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the pr_save_settings() function and insufficient input sanitization. This makes it possible for…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 8:56 p.m.

8.8

CVSS3.1

CVE-2025-10896 - Multiple Plugins <= Multiple Versions - Missing Authorization to Authenticated (Subscriber+) Arbitr…

Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of File with Dangerous Type via arbitrary plugin installation in all versions up to, and including, 1.0.2.3. This is due to missing capability checks on the '*_recommended_upgrade_p…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 8:55 p.m.

6.1

CVSS3.1

CVE-2025-12412 - Top Bar Notification <= 1.12 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation on th tbn_ajax_add() function. This makes it possible for unauthenticated attackers to update the plugin's setti…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 8:53 p.m.

4.3

CVSS3.1

CVE-2025-12188 - Posts Navigation Links for Sections and Headings - Free by WP Masters <= 1.0.1 - Cross-Site Request…

The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the 'wpm_navigation_links_settings' page. This makes it pos…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 8:52 p.m.

5.8

CVSS4.0

CVE-2025-12683 - NULL DACL assigned to Named Pipe communicating with SYSTEM Service

The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained w…

πŸ“… Published: Nov. 4, 2025, 4:23 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 8:50 p.m.
Total resulsts: 316968
Page 17 of 31,697
Β« previous page Β» next page
Filters