4.4

CVSS3.1

CVE-2025-13971 - TWW Protein Calculator <= 1.0.24 - Authenticated (Administrator+) Stored Cross-Site Scripting via '…

The TWW Protein Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Header' setting in all versions up to, and including, 1.0.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:17 p.m.

6.4

CVSS3.1

CVE-2025-13906 - WP Flot <= 0.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The WP Flot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linechart' shortcode in all versions up to, and including, 0.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:16 p.m.

6.1

CVSS3.1

CVE-2025-13988 - 评论小秘书 <= 1.3.2 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The 评论小秘书 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.3.2. This is due to insufficient input sanitization and output escaping on the `$_SERVER['PHP_SELF']` variable in the plugin's settings page…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:16 p.m.

6.4

CVSS3.1

CVE-2025-13966 - Paypal Payment Shortcode <= 1.01 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bu…

The Paypal Payment Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttom_image' parameter of the [paypal-shortcode] shortcode in all versions up to, and including, 1.01 due to insufficient input sanitization and output escaping. This makes it possible for authe…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:16 p.m.

6.4

CVSS3.1

CVE-2025-13961 - Data Visualizer <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Att…

The Data Visualizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'visualize' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

6.4

CVSS3.1

CVE-2025-13884 - Hide Email Address <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode …

The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inline_css' parameter in the `bg-hide-email-address` shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This mak…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:13 p.m.

4.4

CVSS3.1

CVE-2025-14035 - DebateMaster <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Color Option…

The DebateMaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color options in the plugin settings in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administra…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:13 p.m.

6.4

CVSS3.1

CVE-2025-13840 - BUKAZU Search widget <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'short…

The BUKAZU Search widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode' parameter of the 'bukazu_search' shortcode in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 7:23 p.m.

6.4

CVSS3.1

CVE-2025-13960 - GPXpress <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The GPXpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gpxpress' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, …

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:12 p.m.

6.8

CVSS3.1

CVE-2025-13320 - WP User Manager <= 2.9.12 - Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_a…

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_inpu…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 6:23 p.m.
Total resulsts: 343924
Page 2120 of 34,393
« previous page » next page
Filters