7.5

CVSS3.1

CVE-2025-69356 - WordPress TheGem Theme Elements (for Elementor) plugin <= 5.11.0 - Local File Inclusion vulnerabili…

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a thr…

πŸ“… Published: Jan. 6, 2026, 4:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-69355 - WordPress Tickera plugin <= 3.5.6.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.6.4.

πŸ“… Published: Jan. 6, 2026, 4:36 p.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

4.3

CVSS3.1

CVE-2025-69354 - WordPress Better Business Reviews plugin <= 0.1.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1.

πŸ“… Published: Jan. 6, 2026, 4:36 p.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

4.3

CVSS3.1

CVE-2025-69353 - WordPress Proxy & VPN Blocker plugin <= 3.5.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Proxy &amp; VPN Blocker Proxy &amp; VPN Blocker proxy-vpn-blocker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Proxy &amp; VPN Blocker: from n/a through <= 3.5.3.

πŸ“… Published: Jan. 6, 2026, 4:36 p.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

5.4

CVSS3.1

CVE-2025-69352 - WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.15.12.2.

πŸ“… Published: Jan. 6, 2026, 4:36 p.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

8.5

CVSS3.1

CVE-2025-69351 - WordPress Ninja Tables plugin <= 5.2.4 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Blind SQL Injection.This issue affects Ninja Tables: from n/a through <= 5.2.4.

πŸ“… Published: Jan. 6, 2026, 4:36 p.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

5.9

CVSS3.1

CVE-2025-69350 - WordPress Accordion plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accordion accordions-wp allows Stored XSS.This issue affects Accordion: from n/a through <= 3.0.3.

πŸ“… Published: Jan. 6, 2026, 4:36 p.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

5.4

CVSS3.1

CVE-2025-69349 - WordPress RSS Feed Widget plugin <= 3.0.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RSS Feed Widget: from n/a through <= 3.0.2.

πŸ“… Published: Jan. 6, 2026, 4:36 p.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

4.3

CVSS3.1

CVE-2025-69348 - WordPress The Events Calendar Countdown Addon plugin <= 1.4.15 - Broken Access Control vulnerability

Missing Authorization vulnerability in CoolHappy The Events Calendar Countdown Addon countdown-for-the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar Countdown Addon: from n/a through <= 1.4.15.

πŸ“… Published: Jan. 6, 2026, 4:36 p.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

4.3

CVSS3.1

CVE-2025-69346 - WordPress AffiliateX plugin <= 1.3.9.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in WPCenter AffiliateX affiliatex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AffiliateX: from n/a through <= 1.3.9.3.

πŸ“… Published: Jan. 6, 2026, 4:36 p.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.
Total resulsts: 346571
Page 2008 of 34,658
Β« previous page Β» next page
Filters