6.4

CVSS3.1

CVE-2025-14119 - App Landing Template Blocks for WPBakery Page Builder <= 2.0.2 - Authenticated (Contributor+) Store…

The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'atvc_video_play' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied a…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:55 p.m.

4.3

CVSS3.1

CVE-2025-14158 - Coding Blocks <= 1.1.0 - Cross-Site Request Forgery to Settings Update

The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update plugin settings including the …

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:54 p.m.

6.4

CVSS3.1

CVE-2025-13904 - WPGancio <= 1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The WPGancio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gancio-event' shortcode in all versions up to, and including, 1.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:54 p.m.

4.3

CVSS3.1

CVE-2025-14045 - URL Media Uploader <= 1.0.1 - Missing Authorization to Authenticated (Contributor+) Safe File Upload

The URL Media Uploader plugin for WordPress is vulnerable to unauthorized safe file uploads due to a missing capability check on the url_media_uploader_url_upload_ajax_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Contributo…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:54 p.m.

8.8

CVSS3.1

CVE-2025-12968 - Infility Global <= 2.14.42 - Authenticated (Subscriber+) Arbitrary File Upload

The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all versions up to, and including, 2.14.42. This is due to the `upload_file` function in the `infility_import_file` class only validating the MIME type which…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 6:23 p.m.

8.8

CVSS3.1

CVE-2025-12824 - Player Leaderboard 1.0.0 - 1.0.2 - Authenticated (Contributor+) Local File Inclusion

The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2 via the 'player_leaderboard' shortcode. This is due to the plugin using an unsanitized user-supplied value from the shortcode's 'mode' attribute in a call to include() witho…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 15, 2025, 6:16 p.m.

4.3

CVSS3.1

CVE-2025-13408 - Foxtool All-in-One: Contact chat button, Custom login, Media optimize images <= 2.5.2 - Cross-Site …

The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the foxtool_login_google() function. This makes it p…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:48 p.m.

9.8

CVSS3.1

CVE-2025-14344 - Multi Uploader for Gravity Forms <= 1.1.7 - Unauthenticated Arbitrary File Deletion

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'plupload_ajax_delete_file' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to delete arbitra…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 6:24 p.m.

5.3

CVSS3.1

CVE-2025-12883 - Campay Woocommerce Payment Gateway <= 1.2.2 - Unauthenticated Payment Bypass

The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly validating that a transaction has occurred through the payment gateway. This makes it possible for unauthen…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

4.4

CVSS3.1

CVE-2025-14048 - SimplyConvert <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'simplyconver…

The SimplyConvert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'simplyconvert_hash' option in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level …

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:44 p.m.
Total resulsts: 343932
Page 2123 of 34,394
« previous page » next page
Filters