6.1

CVSS3.1

CVE-2025-11496 - Five Star Restaurant Reservations โ€“ WordPress Booking Plugin <= 2.7.5 - Unauthenticated Stored Crosโ€ฆ

The Five Star Restaurant Reservations โ€“ WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenโ€ฆ

๐Ÿ“… Published: Dec. 21, 2025, 2:20 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:37 p.m.

4.3

CVSS3.1

CVE-2023-47232 - WordPress WP Affiliate Disclosure plugin <= 1.2.6 - Broken Access Control + CSRF vulnerability

Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: from n/a through 1.2.6.

๐Ÿ“… Published: Dec. 21, 2025, 12:06 a.m. ๐Ÿ”„ Last Modified: Jan. 6, 2026, 9:15 p.m.

7.7

CVSS3.1

CVE-2023-25446 - WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1.

๐Ÿ“… Published: Dec. 21, 2025, 12:01 a.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

5.4

CVSS3.1

CVE-2023-25445 - WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in HappyFiles HappyFiles Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1.

๐Ÿ“… Published: Dec. 21, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

4.3

CVSS3.1

CVE-2023-25068 - WordPress Magazine Edge theme <= 1.13 - Authenticated Arbitrary Plugin Activation

Missing Authorization vulnerability in Mapro Collins Magazine Edge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Edge: from n/a through 1.13.

๐Ÿ“… Published: Dec. 20, 2025, 11:58 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

6.9

CVSS4.0

CVE-2025-14989 - Campcodes Complete Online Beauty Parlor Management System search-invoices.php sql injection

A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the file /admin/search-invoices.php. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit is publicly available and miโ€ฆ

๐Ÿ“… Published: Dec. 20, 2025, 11:32 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 5:59 a.m.

8.5

CVSS4.0

CVE-2025-34290 - Versa SASE Client for Windows < 7.9.5 Arbitrary Folder Deletion Leading to Local Privilege Escalatiโ€ฆ

Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating tโ€ฆ

๐Ÿ“… Published: Dec. 20, 2025, 8:01 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

7.6

CVSS3.1

CVE-2025-7782 - WP JobHunt <= 7.7 - Missing Authorization to Authenticated (Candidate+) Stored Cross-Site Scriptingโ€ฆ

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due to a missing capability check on the 'cs_update_application_status_callback' function in all versions up to, and including, 7.7. This makes it possible for authenticated attackerโ€ฆ

๐Ÿ“… Published: Dec. 20, 2025, 1:47 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

4.3

CVSS3.1

CVE-2025-7733 - WP JobHunt <= 7.7 - Authenticated (Candidate+) Insecure Direct Object Reference

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.7 via the 'cs_update_application_status_callback' due to missing validation on a user controlled key. This makes it possible for authenticated โ€ฆ

๐Ÿ“… Published: Dec. 20, 2025, 1:47 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

5.4

CVSS3.1

CVE-2025-14298 - FiboSearch โ€“ Ajax Search for WooCommerce <= 1.32.0 - Authenticated (Contributor+) Stored Cross-Siteโ€ฆ

The FiboSearch โ€“ Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up to, and including, 1.32.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makeโ€ฆ

๐Ÿ“… Published: Dec. 20, 2025, 8:22 a.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.
Total resulsts: 343194
Page 1891 of 34,320
ยซ previous page ยป next page
Filters