6.4

CVSS3.1

CVE-2025-13843 - VigLink SpotLight By ShortCode <= 1.0.a - Authenticated (Contributor+) Stored Cross-Site Scripting …

The VigLink SpotLight By ShortCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'float' parameter of the 'spotlight' shortcode in all versions up to, and including, 1.0.a due to insufficient input sanitization and output escaping on user supplied attributes. This makes …

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:32 p.m.

4.3

CVSS3.1

CVE-2025-14391 - Simple Theme Changer <= 1.0 - Cross-Site Request Forgery to Arbitrary Theme Switcher Configuration …

The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted th…

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:31 p.m.

4.3

CVSS3.1

CVE-2025-13366 - Rabbit Hole <= 1.1 - Cross-Site Request Forgery to Settings Reset

The Rabbit Hole plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the plugin's reset functionality. This makes it possible for unauthenticated attackers to reset the plugin's settings v…

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:31 p.m.

6.4

CVSS3.1

CVE-2025-13747 - NewStatPress <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode function in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 7:23 p.m.

6.4

CVSS3.1

CVE-2025-13850 - LS Google Map Router <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortc…

The LS Google Map Router plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'map_type' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level …

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:29 p.m.

6.1

CVSS3.1

CVE-2025-14137 - Simple AL Slider <= 1.2.10 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Simple AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a…

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:28 p.m.

6.4

CVSS3.1

CVE-2025-12650 - Simple post listing <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Simple post listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_name' parameter in the postlist shortcode in all versions up to, and including, 0.2. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: April 8, 2026, 5:28 p.m.

6.1

CVSS3.1

CVE-2025-12834 - Accept Stripe Payments Using Contact Form 7 <= 3.1 - Reflected Cross-Site Scripting via failure_mes…

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failure_message' parameter in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attac…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: April 8, 2026, 7:23 p.m.

8.1

CVSS3.1

CVE-2025-13334 - Blaze Demo Importer 1.0.0 - 1.0.13 - Missing Authorization to Authenticated (Subscriber+) Database …

The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the "blaze_demo_importer_install_demo" function in all versions up to, and including, 1.0.13. This makes it possible for authenticated attackers, with su…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 6:39 p.m.

6.4

CVSS3.1

CVE-2025-12830 - Better Elementor Addons <= 1.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sli…

The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider widget in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: April 8, 2026, 7:23 p.m.
Total resulsts: 343923
Page 2118 of 34,393
Β« previous page Β» next page
Filters