7.1

CVSS3.1

CVE-2025-64232 - WordPress Import from YML plugin <= 3.1.17 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc Import from YML import-from-yml allows Reflected XSS.This issue affects Import from YML: from n/a through <= 3.1.17.

πŸ“… Published: Nov. 6, 2025, 3:56 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 8:19 p.m.

7.1

CVSS3.1

CVE-2025-64224 - WordPress Grand Conference Theme Custom Post Type plugin < 2.6.4 - Cross Site Scripting (XSS) vulne…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Reflected XSS.This issue affects Grand Conference Theme Custom Post Type: from n/a through < 2.6.4.

πŸ“… Published: Nov. 6, 2025, 3:56 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 8:19 p.m.

7.1

CVSS3.1

CVE-2025-64198 - WordPress Easy Social Share Buttons plugin < 10.7.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Easy Social Share Buttons easy-social-share-buttons3 allows Reflected XSS.This issue affects Easy Social Share Buttons: from n/a through < 10.7.1.

πŸ“… Published: Nov. 6, 2025, 3:56 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 8:38 p.m.

7.1

CVSS3.1

CVE-2025-64196 - WordPress Booster for WooCommerce plugin <= 7.2.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Reflected XSS.This issue affects Booster for WooCommerce: from n/a through <= 7.2.5.

πŸ“… Published: Nov. 6, 2025, 3:56 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 8:38 p.m.

10

CVSS3.1

CVE-2025-6327 - WordPress King Addons for Elementor plugin <= 51.1.36 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons allows Upload a Web Shell to a Web Server.This issue affects King Addons for Elementor: from n/a through <= 51.1.36.

πŸ“… Published: Nov. 6, 2025, 3:56 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 8:38 p.m.

9.8

CVSS3.1

CVE-2025-6325 - WordPress King Addons for Elementor plugin <= 51.1.36 - Privilege Escalation vulnerability

Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Escalation.This issue affects King Addons for Elementor: from n/a through <= 51.1.36.

πŸ“… Published: Nov. 6, 2025, 3:56 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 8:38 p.m.

4.3

CVSS3.1

CVE-2025-62950 - WordPress Contest Gallery plugin <= 28.0.0 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Cross Site Request Forgery.This issue affects Contest Gallery: from n/a through <= 28.0.0.

πŸ“… Published: Nov. 6, 2025, 3:56 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 8:38 p.m.

6.5

CVSS3.1

CVE-2025-62914 - WordPress Effect Maker plugin <= 1.2.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in anibalwainstein Effect Maker effect-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Effect Maker: from n/a through <= 1.2.1.

πŸ“… Published: Nov. 6, 2025, 3:56 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 8:38 p.m.

7.1

CVSS3.1

CVE-2025-62076 - WordPress Simple Payment plugin <= 2.4.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ido Kobelkowsky Simple Payment simple-payment.This issue affects Simple Payment: from n/a through <= 2.4.6.

πŸ“… Published: Nov. 6, 2025, 3:55 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 8:19 p.m.

7.3

CVSS3.1

CVE-2025-62075 - WordPress Simple Payment plugin <= 2.4.6 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ido Kobelkowsky Simple Payment simple-payment.This issue affects Simple Payment: from n/a through <= 2.4.6.

πŸ“… Published: Nov. 6, 2025, 3:55 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 8:19 p.m.
Total resulsts: 317431
Page 23 of 31,744
Β« previous page Β» next page
Filters