7.1

CVSS3.1

CVE-2025-27002 - WordPress CountDown With Image or Video Background plugin <= 1.5 - Reflected Cross Site Scripting (…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup CountDown With Image or Video Background countdown-with-background allows Reflected XSS.This issue affects CountDown With Image or Video Background: from n/a through <= 1.5.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

9.3

CVSS3.1

CVE-2025-23993 - WordPress Felan Framework plugin <= 1.1.3 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allows SQL Injection.This issue affects Felan Framework: from n/a through <= 1.1.3.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

9.8

CVSS3.1

CVE-2025-23504 - WordPress Felan Framework plugin <= 1.1.3 - Account Takeover vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allows Authentication Abuse.This issue affects Felan Framework: from n/a through <= 1.1.3.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2025-22728 - WordPress Workreap (theme's plugin) plugin <= 3.3.6 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows SQL Injection.This issue affects Workreap (theme's plugin): from n/a through <= 3.3.6.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

6.4

CVSS3.1

CVE-2025-22726 - WordPress nK Themes Helper plugin <= 1.7.9 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request Forgery.This issue affects nK Themes Helper: from n/a through <= 1.7.9.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

7.1

CVSS3.1

CVE-2025-22725 - WordPress WP Virtual Assistant plugin <= 3.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Stored XSS.This issue affects WP Virtual Assistant: from n/a through <= 3.1.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

7.5

CVSS3.1

CVE-2025-22715 - WordPress WP Attractive Donations System - Easy Stripe & Paypal donations plugin <= 1.25 - Arbitrar…

Missing Authorization vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from…

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

8.5

CVSS3.1

CVE-2025-22713 - WordPress WooCommerce Orders & Customers Exporter plugin <= 5.4 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommerce Orders & Customers Exporter woocommerce-orders-ei allows SQL Injection.This issue affects WooCommerce Orders & Customers Exporter: from n/a through <= 5.4.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

8.1

CVSS3.1

CVE-2025-22712 - WordPress Typify theme <= 3.0.2 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QantumThemes Typify typify allows PHP Local File Inclusion.This issue affects Typify: from n/a through <= 3.0.2.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

8.1

CVSS3.1

CVE-2025-22708 - WordPress Mitech theme <= 2.3.4 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allows PHP Local File Inclusion.This issue affects Mitech: from n/a through <= 2.3.4.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.
Total resulsts: 349182
Page 2232 of 34,919
Β« previous page Β» next page
Filters