4.3

CVSS3.1

CVE-2025-62150 - WordPress History Timeline plugin <= 1.0.6 - Broken Access Control vulnerability

Missing Authorization vulnerability in themesawesome History Timeline timeline-awesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects History Timeline: from n/a through <= 1.0.6.

πŸ“… Published: Dec. 31, 2025, 3:42 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

4.3

CVSS3.1

CVE-2025-62154 - WordPress AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One plugin…

Missing Authorization vulnerability in recorp AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One ai-content-writing-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Content Writing Assistant (Content Writer, Chat…

πŸ“… Published: Dec. 31, 2025, 3:41 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.3

CVSS3.1

CVE-2025-62114 - WordPress Download Media Library plugin <= 0.2.1 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in marcelotorres Download Media Library download-media-library allows Retrieve Embedded Sensitive Data.This issue affects Download Media Library: from n/a through <= 0.2.1.

πŸ“… Published: Dec. 31, 2025, 3:40 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.3

CVSS3.1

CVE-2025-62116 - WordPress AI Copilot plugin <= 1.5.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in quadlayers AI Copilot ai-copilot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Copilot: from n/a through <= 1.5.2.

πŸ“… Published: Dec. 31, 2025, 3:39 p.m. πŸ”„ Last Modified: April 28, 2026, 4:14 p.m.

5.3

CVSS3.1

CVE-2025-62122 - WordPress Trash Duplicate and 301 Redirect plugin <= 1.9.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in solwininfotech Trash Duplicate and 301 Redirect trash-duplicate-and-301-redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trash Duplicate and 301 Redirect: from n/a through <= 1.9.1.

πŸ“… Published: Dec. 31, 2025, 3:38 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.3

CVSS3.1

CVE-2025-62079 - WordPress WP Export Categories & Taxonomies plugin <= 1.0.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Damian WP Export Categories & Taxonomies wp-export-categories-taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Export Categories & Taxonomies: from n/a through <= 1.0.3.

πŸ“… Published: Dec. 31, 2025, 3:37 p.m. πŸ”„ Last Modified: April 28, 2026, 4:14 p.m.

5.3

CVSS3.1

CVE-2025-62126 - WordPress Varnish/Nginx Proxy Caching plugin <= 1.8.3 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Razvan Stanga Varnish/Nginx Proxy Caching vcaching allows Retrieve Embedded Sensitive Data.This issue affects Varnish/Nginx Proxy Caching: from n/a through <= 1.8.3.

πŸ“… Published: Dec. 31, 2025, 3:36 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.3

CVSS3.1

CVE-2025-49338 - WordPress Flowbox plugin <= 1.1.6 - Broken Access Control vulnerability

Missing Authorization vulnerability in Flowbox Flowbox flowbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flowbox: from n/a through <= 1.1.6.

πŸ“… Published: Dec. 31, 2025, 3:35 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

5.3

CVSS3.1

CVE-2025-62747 - WordPress Featured Image Generator plugin <= 1.3.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in Aum Watcharapon Featured Image Generator featured-image-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Image Generator: from n/a through <= 1.3.4.

πŸ“… Published: Dec. 31, 2025, 3:33 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.3

CVSS4.0

CVE-2025-15390 - PHPGurukul Small CRM edit-user.php authorization

A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attack…

πŸ“… Published: Dec. 31, 2025, 3:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.
Total resulsts: 347893
Page 2196 of 34,790
Β« previous page Β» next page
Filters