5.3

CVSS3.1

CVE-2025-15475 - PayHere Payment Gateway Plugin for WooCommerce <= 2.3.9 - Missing Authorization to Unauthenticated …

The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to …

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 20, 2026, 9:15 p.m.

4.3

CVSS3.1

CVE-2025-15376 - Stopwords for comments <= 1.1 - Missing Authorization to Cross-Site Request Forgery

The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing nonce validation on the 'set_stopwords_for_comments' and 'delete_stopwords_for_comments' functions. This makes it possible for unauthenticate…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-14173 - Perfit WooCommerce <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings De…

The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. This is due to missing authorization checks on the `logout` function called via the `actions` function hooked to `admin_init`. This makes it possible for unauthenticated a…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-14846 - SocialChamp with WordPress <= 1.3.5 - Cross-Site Request Forgery to Plugin Settings Update

The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.5. This is due to missing nonce validation on the wpsc_settings_tab_menu function. This makes it possible for unauthenticated attackers to modify plugin settings…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-15513 - Float Payment Gateway <= 1.1.9 - Improper Authorization to Unauthenticated Order Status Manipulation

The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error handling in the verifyFloatResponse() function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to mark any WooCommerce order as f…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 20, 2026, 9:15 p.m.

4.4

CVSS3.1

CVE-2026-0741 - Electric Studio Download Counter <= 2.4 - Authenticated (Administrator+) Stored Cross-Site Scriptin…

The Electric Studio Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 16, 2026, 2:15 a.m.

5.3

CVSS3.1

CVE-2025-15512 - Aplazo Payment Gateway <= 1.4.3 - Missing Authorization to Unauthenticated Order Status Manipulation

The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_success_response() function in all versions up to, and including, 1.4.3. This makes it possible for unauthenticated attackers to set any WooCommerce orde…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2026-0813 - Short Link <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Administration S…

The Short Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'short_link_post_title' and 'short_link_page_title' parameters in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 16, 2026, 6:15 p.m.

4.4

CVSS3.1

CVE-2026-0734 - WP Allowed Hosts <= 1.0.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'allowed…

The WP Allowed Hosts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allowed-hosts' parameter in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-lev…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 16, 2026, 6:15 p.m.

4.4

CVSS3.1

CVE-2026-0812 - LinkedIn SC <= 1.1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Page

The LinkedIn SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'linkedin_sc_date_format', 'linkedin_sc_api_key', and 'linkedin_sc_secret_key' parameters in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it p…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 16, 2026, 6:15 p.m.
Total resulsts: 345317
Page 1747 of 34,532
« previous page » next page
Filters