6.4

CVSS3.1

CVE-2026-0833 - Team Section Block <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social N…

The Team Section Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user-supplied social network link URLs. This makes it possible for authenticated …

📅 Published: Jan. 17, 2026, 6:42 a.m. 🔄 Last Modified: April 16, 2026, 6:15 p.m.

5.3

CVSS3.1

CVE-2025-12825 - User Registration Using Contact Form 7 <= 2.5 - Authenticated (Subscriber+) Information Exposure

The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_cf7_form_data' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to retrieve form setting…

📅 Published: Jan. 17, 2026, 4:34 a.m. 🔄 Last Modified: April 22, 2026, midnight

4.3

CVSS3.1

CVE-2025-12168 - Phrase TMS Integration for WordPress <= 4.7.5 - Missing Authorization to Authenticated (Subscriber+…

The Phrase TMS Integration for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_delete_log' AJAX endpoint in all versions up to, and including, 4.7.5. This makes it possible for authenticated attackers, with Subscrib…

📅 Published: Jan. 17, 2026, 4:34 a.m. 🔄 Last Modified: April 22, 2026, noon

5.3

CVSS3.1

CVE-2025-14029 - Community Events <= 1.5.6 - Missing Authorization to Unauthenticated Arbitrary Event Approval via '…

The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_admin_event_approval() function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to approve arbitrary events vi…

📅 Published: Jan. 17, 2026, 4:34 a.m. 🔄 Last Modified: April 22, 2026, 8:15 p.m.

5.3

CVSS3.1

CVE-2025-14463 - Payment Button for PayPal <= 1.2.3.41 - Missing Authorization to Unauthenticated Arbitrary Order Cr…

The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 1.2.3.41. This is due to the plugin exposing a public AJAX endpoint (`wppaypalcheckout_ajax_process_order`) that processes checkout results without any authenticatio…

📅 Published: Jan. 17, 2026, 3:24 a.m. 🔄 Last Modified: April 22, 2026, midnight

6.5

CVSS3.1

CVE-2025-13725 - Gutenberg Thim Blocks <= 1.0.1 - Authenticated (Contributor+) Arbitrary File Read via 'iconSVG' Par…

The Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 1.0.1. This is due to insufficient path validation in the server-side rendering of the thim-blocks/icon block. This makes …

📅 Published: Jan. 17, 2026, 3:24 a.m. 🔄 Last Modified: April 21, 2026, 4:30 p.m.

2.2

CVSS3.1

CVE-2026-0682 - Church Admin <= 5.0.28 - Authenticated (Administrator+) Blind Server-Side Request Forgery via 'audi…

The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.28 due to insufficient validation of user-supplied URLs in the 'audio_url' parameter. This makes it possible for authenticated attackers, with Administrator-level access, to …

📅 Published: Jan. 17, 2026, 3:24 a.m. 🔄 Last Modified: April 16, 2026, 8 a.m.

4.3

CVSS3.1

CVE-2026-0820 - RepairBuddy <= 4.1116 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary S…

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116. This makes it possible for auth…

📅 Published: Jan. 17, 2026, 3:24 a.m. 🔄 Last Modified: April 15, 2026, 10 p.m.

5.9

CVSS3.1

CVE-2025-12002 - Feeds for YouTube Pro <= 2.6.0 - Unauthenticated Arbitrary File Read via Path Traversal

The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.6.0 via the 'sby_check_wp_submit' AJAX action. This is due to insufficient sanitization of user-supplied data and the use of that data in a file operation. This makes it possi…

📅 Published: Jan. 17, 2026, 2:22 a.m. 🔄 Last Modified: April 21, 2026, 4:30 p.m.

5.8

CVSS3.1

CVE-2025-12718 - Quick Contact Form <= 8.2.6 - Unauthenticated Open Mail Relay

The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6. This is due to the 'qcf_validate_form' AJAX endpoint allowing a user controlled parameter to set the 'from' email address. This makes it possible for unauthenticated attackers t…

📅 Published: Jan. 17, 2026, 2:22 a.m. 🔄 Last Modified: April 21, 2026, 12:30 a.m.
Total resulsts: 349182
Page 2088 of 34,919
« previous page » next page
Filters