6.4

CVSS3.1

CVE-2025-4776 - Phlox <= 2.17.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-caption` HTML …

The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all versions up to, and including, 2.17.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access…

📅 Published: Jan. 6, 2026, 6:36 a.m. 🔄 Last Modified: April 20, 2026, 9:30 p.m.

5.3

CVSS3.1

CVE-2025-13215 - Shortcodes and extra features for Phlox theme <= 2.17.13 - Unauthenticated Draft Posts Information …

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.17.13 via the auxels_ajax_search due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers…

📅 Published: Jan. 6, 2026, 6:36 a.m. 🔄 Last Modified: April 21, 2026, 5 p.m.

8.7

CVSS4.0

CVE-2026-21411 - Authentication Bypass Allowing Administrator Password Modification

Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and change the password.

📅 Published: Jan. 6, 2026, 6:34 a.m. 🔄 Last Modified: April 18, 2026, 8:15 p.m.

8.8

CVSS3.1

CVE-2025-14997 - BuddyPress Xprofile Custom Field Types <= 1.2.8 - Authenticated (Subscriber+) Arbitrary File Deleti…

The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_field' function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Subscriber-level acc…

📅 Published: Jan. 6, 2026, 4:31 a.m. 🔄 Last Modified: April 22, 2026, 12:15 a.m.

6.4

CVSS3.1

CVE-2025-14120 - URL Image Importer <= 1.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uplo…

The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.7 due to insufficient sanitization of SVG files. This makes it possible for authenticated attackers, with Author-level access and above, to inject …

📅 Published: Jan. 6, 2026, 4:31 a.m. 🔄 Last Modified: April 21, 2026, 5 p.m.

6.4

CVSS3.1

CVE-2025-14438 - Xagio SEO <= 7.1.0.30 - Authenticated (Subscriber+) Server-Side Request Forgery

The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.1.0.30 via the 'pixabayDownloadImage' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests t…

📅 Published: Jan. 6, 2026, 4:31 a.m. 🔄 Last Modified: April 21, 2026, 5 p.m.

4.3

CVSS3.1

CVE-2025-14441 - Popupkit <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Subscriber Data …

The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on the DELETE `/subscribers` REST API endpoint in all versions up to, and including, 2.2.0. This is due to the `permission_callback` only validating wp_rest nonce without checking user…

📅 Published: Jan. 6, 2026, 4:31 a.m. 🔄 Last Modified: April 21, 2026, 5 p.m.

9.8

CVSS3.1

CVE-2025-15001 - FS Registration Password <= 1.0.1 - Unauthenticated Privilege Escalation via Account Takeover

The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated …

📅 Published: Jan. 6, 2026, 4:31 a.m. 🔄 Last Modified: April 22, 2026, 4 p.m.

9.8

CVSS3.1

CVE-2025-14996 - AS Password Field In Default Registration Form <= 2.0.0 - Unauthenticated Privilege Escalation via …

The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possibl…

📅 Published: Jan. 6, 2026, 4:31 a.m. 🔄 Last Modified: April 22, 2026, 4 p.m.

7.8

CVSS3.1

CVE-2026-21486 - Use After Free and Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds …

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below contain Use After Free, Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write vulnerabilities in its CIccSparseMatrix::CIccSparseMatrix function. T…

📅 Published: Jan. 6, 2026, 3:36 a.m. 🔄 Last Modified: April 18, 2026, 5 p.m.
Total resulsts: 348130
Page 2170 of 34,813
« previous page » next page
Filters