4.3

CVSS3.1

CVE-2025-14062 - Animated Pixel Marquee Creator <= 1.0.0 - Cross-Site Request Forgery via 'marquee' Parameter

The Animated Pixel Marquee Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery via the 'marquee' parameter in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the marquee deletion function. This makes it possible for unauthenticated attackers…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 4:22 p.m.

9.8

CVSS3.1

CVE-2025-12963 - LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart <= 1.2.29 - Missin…

The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.29. This is due to the plugin not properly validating a user's identity via the 'wp-json/laz…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 18, 2025, 8:50 p.m.

6.1

CVSS3.1

CVE-2025-14132 - Category Dropdown List <= 1.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Category Dropdown List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injec…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 18, 2025, 8:37 p.m.

4.4

CVSS3.1

CVE-2025-13971 - TWW Protein Calculator <= 1.0.24 - Authenticated (Administrator+) Stored Cross-Site Scripting via '…

The TWW Protein Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Header' setting in all versions up to, and including, 1.0.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 15, 2025, 6:12 p.m.

6.4

CVSS3.1

CVE-2025-13906 - WP Flot <= 0.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The WP Flot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linechart' shortcode in all versions up to, and including, 0.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 15, 2025, 6:12 p.m.

6.1

CVSS3.1

CVE-2025-13988 - 评论小秘书 <= 1.3.2 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The 评论小秘书 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.3.2. This is due to insufficient input sanitization and output escaping on the `$_SERVER['PHP_SELF']` variable in the plugin's settings page…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 15, 2025, 6:12 p.m.

6.4

CVSS3.1

CVE-2025-13966 - Paypal Payment Shortcode <= 1.01 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bu…

The Paypal Payment Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttom_image' parameter of the [paypal-shortcode] shortcode in all versions up to, and including, 1.01 due to insufficient input sanitization and output escaping. This makes it possible for authe…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 15, 2025, 6:13 p.m.

6.4

CVSS3.1

CVE-2025-13961 - Data Visualizer <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Att…

The Data Visualizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'visualize' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 4:20 p.m.

6.4

CVSS3.1

CVE-2025-13884 - Hide Email Address <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode …

The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inline_css' parameter in the `bg-hide-email-address` shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This mak…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:17 p.m.

4.4

CVSS3.1

CVE-2025-14035 - DebateMaster <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Color Option…

The DebateMaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color options in the plugin settings in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administra…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:17 p.m.
Total resulsts: 342867
Page 2014 of 34,287
« previous page » next page
Filters