6.1

CVSS3.1

CVE-2025-14118 - Starred Review <= 1.4.2 - Reflected Cross-Site Scripting via PHP_SELF Variable

The Starred Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the PHP_SELF variable in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri…

📅 Published: Jan. 7, 2026, 9:20 a.m. 🔄 Last Modified: April 22, 2026, 4 p.m.

4.4

CVSS3.1

CVE-2025-14028 - Contact Us Simple Form <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plug…

The Contact Us Simple Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with …

📅 Published: Jan. 7, 2026, 9:20 a.m. 🔄 Last Modified: April 22, 2026, 4 p.m.

6.4

CVSS3.1

CVE-2025-14796 - My Album Gallery <= 1.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title

The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image titles in all versions up to, and including, 1.0.4. This is due to insufficient input sanitization and output escaping on the 'attachment->title' attribute. This makes it possible for authenticated atta…

📅 Published: Jan. 7, 2026, 9:20 a.m. 🔄 Last Modified: April 22, 2026, 4 p.m.

6.1

CVSS3.1

CVE-2025-14128 - Stumble! for WordPress <= 1.1.1 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Stumble! for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj…

📅 Published: Jan. 7, 2026, 9:20 a.m. 🔄 Last Modified: April 22, 2026, 8:15 p.m.

6.1

CVSS3.1

CVE-2025-14127 - Testimonial Master <= 0.2.1 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Testimonial Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject …

📅 Published: Jan. 7, 2026, 9:20 a.m. 🔄 Last Modified: April 22, 2026, 8:30 p.m.

6.4

CVSS3.1

CVE-2025-13667 - WP Recipe Manager <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Skill Le…

The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input field in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated atta…

📅 Published: Jan. 7, 2026, 9:20 a.m. 🔄 Last Modified: April 22, 2026, 4 p.m.

6.4

CVSS3.1

CVE-2025-14109 - AH Shortcodes <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'column' Shor…

The AH Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column' shortcode attribute in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…

📅 Published: Jan. 7, 2026, 9:20 a.m. 🔄 Last Modified: April 22, 2026, 4 p.m.

5.3

CVSS3.1

CVE-2025-13694 - AA Block country <= 1.0.1 - Unauthenticated IP Address Spoofing via X-Forwarded-For Header

The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. This is due to the plugin trusting user-supplied headers such as HTTP_X_FORWARDED_FOR to determine the client's IP address without proper validation or considering if the server i…

📅 Published: Jan. 7, 2026, 9:20 a.m. 🔄 Last Modified: April 22, 2026, 4 p.m.

6.4

CVSS3.1

CVE-2025-14053 - Travel Bucket List <= 0.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcod…

The Wish To Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 0.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Cont…

📅 Published: Jan. 7, 2026, 9:20 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-13847 - PhotoFade <= 0.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribu…

The PhotoFade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'time' parameter in all versions up to, and including, 0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abov…

📅 Published: Jan. 7, 2026, 9:20 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346624
Page 2000 of 34,663
« previous page » next page
Filters