4.3

CVSS3.1

CVE-2025-13628 - Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated …

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability check on the 'bulk_action_handler' and 'coupon_permanent_delete' functions in all versions up to, and including, 3.9.3. This makes it…

📅 Published: Jan. 9, 2026, 7:22 a.m. 🔄 Last Modified: Jan. 9, 2026, 7:22 a.m.

7.2

CVSS3.1

CVE-2025-14937 - Frontend Admin by DynamiApps <= 3.28.23 - Unauthenticated Stored Cross-Site Scripting via 'update_f…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/forms/update_field' AJAX action in all versions up to, and including, 3.28.23 due to insufficient input sanitization and output escaping. This makes it …

📅 Published: Jan. 9, 2026, 7:22 a.m. 🔄 Last Modified: Jan. 9, 2026, 7:22 a.m.

5.3

CVSS3.1

CVE-2025-14146 - Booking Calendar <= 10.14.10 - Unauthenticated Sensitive Information Exposure

The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPBC_FLEXTIMELINE_NAV` AJAX action. This is due to the nonce verification being conditionally disabled by default (`booking_is_nonce_at_front_end` option…

📅 Published: Jan. 9, 2026, 7:22 a.m. 🔄 Last Modified: Jan. 9, 2026, 7:22 a.m.

8.2

CVSS4.0

CVE-2026-21409 -

Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID …

📅 Published: Jan. 9, 2026, 7:15 a.m. 🔄 Last Modified: Jan. 9, 2026, 7:15 a.m.

10

CVSS3.1

CVE-2025-70974 -

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-su…

📅 Published: Jan. 9, 2026, 6:43 a.m. 🔄 Last Modified: Jan. 9, 2026, 6:43 a.m.

5.3

CVSS3.1

CVE-2025-14574 - weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.1.15 - Unauthenticat…

The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.15 via the `/wp-json/wp/v2/docs/settings` REST API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including third party services API ke…

📅 Published: Jan. 9, 2026, 6:34 a.m. 🔄 Last Modified: Jan. 9, 2026, 6:34 a.m.

6.4

CVSS3.1

CVE-2025-14893 - IndieWeb <= 4.0.5 - Authenticated (Author+) Stored Cross-Site Scripting via 'Telephone' Parameter

The IndieWeb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Telephone' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author level access and above…

📅 Published: Jan. 9, 2026, 6:34 a.m. 🔄 Last Modified: Jan. 9, 2026, 6:34 a.m.

7.2

CVSS3.1

CVE-2025-15055 - SlimStat Analytics <= 5.3.4 - Unauthenticated Stored Cross-Site Scripting via 'notes/resource' Para…

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' parameters in all versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a…

📅 Published: Jan. 9, 2026, 6:34 a.m. 🔄 Last Modified: Jan. 9, 2026, 6:34 a.m.

7.2

CVSS3.1

CVE-2025-15057 - SlimStat Analytics <= 5.3.3 - Unauthenticated Stored Cross-Site Scripting via 'fh' Parameter

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) parameter in all versions up to, and including, 5.3.3. This is due to insufficient input sanitization and output escaping on the fingerprint value stored in the database. This makes i…

📅 Published: Jan. 9, 2026, 6:34 a.m. 🔄 Last Modified: Jan. 9, 2026, 6:34 a.m.

5.4

CVSS3.1

CVE-2025-14718 - Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Cat…

The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attack…

📅 Published: Jan. 9, 2026, 6:34 a.m. 🔄 Last Modified: Jan. 9, 2026, 6:34 a.m.
Total resulsts: 326833
Page 2 of 32,684
« previous page » next page
Filters