5.3

CVSS3.1

CVE-2025-13381 - AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Missing Authorization to Unauthenti…

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to uploa…

📅 Published: Nov. 27, 2025, 9:27 a.m. 🔄 Last Modified: Nov. 27, 2025, 9:27 a.m.

5.3

CVSS3.1

CVE-2025-12584 - Quick View for WooCommerce <= 2.2.17 - Unauthenticated Private Product Disclosure

The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX endpoint due to insufficient restrictions on which products can be included. This makes it possible for unauthenticated attackers t…

📅 Published: Nov. 27, 2025, 9:27 a.m. 🔄 Last Modified: Nov. 27, 2025, 9:27 a.m.

6.5

CVSS3.1

CVE-2025-13378 - AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Unauthenticated Server-Side Request…

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.0 via the ays_chatgpt_pinecone_upsert function. This makes it possible for unauthenticated attackers to make web requests to arbitrary…

📅 Published: Nov. 27, 2025, 9:27 a.m. 🔄 Last Modified: Nov. 27, 2025, 9:27 a.m.

5.4

CVSS3.1

CVE-2025-59026 -

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No publicly…

📅 Published: Nov. 27, 2025, 9:23 a.m. 🔄 Last Modified: Nov. 27, 2025, 9:23 a.m.

6.1

CVSS3.1

CVE-2025-59025 -

Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Sanitization has been updated to avoid such bypasses. No publicly available exploits are known

📅 Published: Nov. 27, 2025, 9:23 a.m. 🔄 Last Modified: Nov. 27, 2025, 9:23 a.m.

5.4

CVSS3.1

CVE-2025-30190 -

Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No publicly available expl…

📅 Published: Nov. 27, 2025, 9:23 a.m. 🔄 Last Modified: Nov. 27, 2025, 9:23 a.m.

5.4

CVSS3.1

CVE-2025-30186 -

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No publicly…

📅 Published: Nov. 27, 2025, 9:23 a.m. 🔄 Last Modified: Nov. 27, 2025, 9:23 a.m.

8.8

CVSS3.1

CVE-2025-13536 - Blubrry PowerPress <= 11.15.2 - Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_…

The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting execution when validation fails in the 'powerpress_edit_po…

📅 Published: Nov. 27, 2025, 8:27 a.m. 🔄 Last Modified: Nov. 27, 2025, 8:27 a.m.

5.3

CVSS3.1

CVE-2025-13157 - QODE Wishlist for WooCommerce <= 1.2.7 - Unauthenticated Insecure Direct Object Reference to Wishli…

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the 'qode_wishlist_for_woocommerce_wishlist_table_item_callback' function due to missing validation on a user controlled key. This makes it possib…

📅 Published: Nov. 27, 2025, 6:42 a.m. 🔄 Last Modified: Nov. 27, 2025, 6:42 a.m.

5.3

CVSS3.1

CVE-2025-13441 - Hide Category by User Role for WooCommerce <= 2.3.1 - Missing Authorization to Unauthenticated Cach…

The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This is due to a missing capability check on the admin_init hook that executes wp_cache_flush(). This makes it possible for unauthenticated attacke…

📅 Published: Nov. 27, 2025, 6:42 a.m. 🔄 Last Modified: Nov. 27, 2025, 6:42 a.m.
Total resulsts: 319557
Page 2 of 31,956
« previous page » next page
Filters