9.8

CVSS3.1

CVE-2025-67911 - WordPress Newsletters plugin <= 4.11 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-67910 - WordPress Contentstudio plugin <= 1.3.7 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.This issue affects Contentstudio: from n/a through <= 1.3.7.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

7.1

CVSS3.1

CVE-2025-27004 - WordPress Famous - Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflect…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Famous - Responsive Image And Video Grid Gallery WordPress Plugin famous_grid_image_and_video_gallery allows Reflected XSS.This issue affects Famous - Responsive Image And Video Grid G…

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

7.1

CVSS3.1

CVE-2025-27002 - WordPress CountDown With Image or Video Background plugin <= 1.5 - Reflected Cross Site Scripting (…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup CountDown With Image or Video Background countdown-with-background allows Reflected XSS.This issue affects CountDown With Image or Video Background: from n/a through <= 1.5.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

9.3

CVSS3.1

CVE-2025-23993 - WordPress Felan Framework plugin <= 1.1.3 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allows SQL Injection.This issue affects Felan Framework: from n/a through <= 1.1.3.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

9.8

CVSS3.1

CVE-2025-23504 - WordPress Felan Framework plugin <= 1.1.3 - Account Takeover vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allows Authentication Abuse.This issue affects Felan Framework: from n/a through <= 1.1.3.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2025-22728 - WordPress Workreap (theme's plugin) plugin <= 3.3.6 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows SQL Injection.This issue affects Workreap (theme's plugin): from n/a through <= 3.3.6.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

6.4

CVSS3.1

CVE-2025-22726 - WordPress nK Themes Helper plugin <= 1.7.9 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request Forgery.This issue affects nK Themes Helper: from n/a through <= 1.7.9.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

7.1

CVSS3.1

CVE-2025-22725 - WordPress WP Virtual Assistant plugin <= 3.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Stored XSS.This issue affects WP Virtual Assistant: from n/a through <= 3.1.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

7.5

CVSS3.1

CVE-2025-22715 - WordPress WP Attractive Donations System - Easy Stripe & Paypal donations plugin <= 1.25 - Arbitrar…

Missing Authorization vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from…

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.
Total resulsts: 348415
Page 2155 of 34,842
Β« previous page Β» next page
Filters