6.1

CVSS3.1

CVE-2025-14129 - Like DisLike Voting <= 1.0.1 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Like DisLike Voting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:42 p.m.

6.4

CVSS3.1

CVE-2025-13989 - WP Dropzone <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'callback' Shor…

The WP Dropzone plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callback' shortcode attribute in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on user-supplied 'callback' attributes, which are evaluated as Jav…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

6.1

CVSS3.1

CVE-2025-14125 - Complag <= 1.0.2 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Complag plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:38 p.m.

6.4

CVSS3.1

CVE-2025-14393 - Wpik WordPress Basic Ajax Form <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:38 p.m.

6.4

CVSS3.1

CVE-2025-14143 - Ayo Shortcodes <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortc…

The Ayo Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' parameter of the ayo_action shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with C…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:37 p.m.

4.9

CVSS3.1

CVE-2025-13972 - WatchTowerHQ <= 3.16.0 - Authenticated (Administrator+) Arbitrary File Read via 'wht_download_big_o…

The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' parameter in all versions up to, and including, 3.16.0. This is due to insufficient path validation in the handle_big_object_download_request function. This makes it possible for auth…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:36 p.m.

5.4

CVSS3.1

CVE-2025-14064 - BuddyTask <= 1.3.0 - Missing Authorization to Authenticated (Subscriber+) Cross-Group Task Board Ac…

The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple AJAX endpoints in all versions up to, and including, 1.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to v…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

4.4

CVSS3.1

CVE-2025-14467 - WP Job Portal <= 2.4.4 - Authenticated (Editor+) Stored Cross-Site Scripting via Job Description Fi…

The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.4. This is due to the plugin explicitly whitelisting the `<script>` tag in its `WPJOBPORTAL_ALLOWED_TAGS` configuration and using insufficient input sanitization when saving…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

6.4

CVSS3.1

CVE-2025-13889 - Simple Nivo Slider <= 0.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcod…

The Simple Nivo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode parameter in all versions up to, and including, 0.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-leve…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:35 p.m.

4.3

CVSS3.1

CVE-2025-14170 - Vimeo SimpleGallery <= 0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin …

The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 0.2. This is due to missing authorization checks on the `vimeogallery_admin` function hooked to `admin_menu`. This makes it possible for authenticated attackers, with Subscriber…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.
Total resulsts: 343942
Page 2125 of 34,395
« previous page » next page
Filters