4.4

CVSS3.1

CVE-2025-13682 - Trail Manager <= 1.0.0 - Authenticated (Admin+) Stored Cross-Site Scripting

The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…

📅 Published: Dec. 5, 2025, 9:27 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

8.1

CVSS3.1

CVE-2025-13614 - Cool Tag Cloud <= 2.29 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' shortcode in all versions up to, and including, 2.29 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: Dec. 5, 2025, 9:27 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

6.4

CVSS3.1

CVE-2025-13678 - Thai Lottery Widget <= 2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode…

The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcode in all versions up to, and including, 2.5. This is due to insufficient input sanitization and output escaping on the user supplied `width` and `height` shortcode attributes. Thi…

📅 Published: Dec. 5, 2025, 9:27 a.m. 🔄 Last Modified: April 8, 2026, 5:09 p.m.

5.3

CVSS3.1

CVE-2025-12876 - Projectopia – WordPress Project Management <= 5.1.19 - Missing Authorization to Unauthenticated Arb…

The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pto_delete_file AJAX action in all versions up to, and including, 5.1.19. This makes it possible for unauthenticated attackers to delete ar…

📅 Published: Dec. 5, 2025, 9:27 a.m. 🔄 Last Modified: April 8, 2026, 6:23 p.m.

8.8

CVSS3.1

CVE-2025-12879 - User Generator and Importer <= 1.2.2 - Cross-Site Request Forgery to Privilege Escalation via Arbit…

The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce validation in the "Import Using CSV File" function. This makes it possible for unauthenticated attackers to elevate user privileges by…

📅 Published: Dec. 5, 2025, 9:27 a.m. 🔄 Last Modified: April 8, 2026, 5:03 p.m.

6.4

CVSS3.1

CVE-2025-13739 - CryptX <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wi…

📅 Published: Dec. 5, 2025, 9:27 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

8.1

CVSS3.1

CVE-2025-12851 - My auctions allegro <= 3.6.32 - Unauthenticated Local File Inclusion via controller

The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.32 via the 'controller' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PH…

📅 Published: Dec. 5, 2025, 9:27 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

4.3

CVSS3.1

CVE-2025-12130 - WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Sit…

The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.4. This is due to missing or incorrect nonce validation on the /vendor_dashboard/product/delete/ endpoint. Th…

📅 Published: Dec. 5, 2025, 7:26 a.m. 🔄 Last Modified: April 8, 2026, 5:29 p.m.

4.3

CVSS3.1

CVE-2025-13684 - ARK Related Posts <= 2.19 - Cross-Site Request Forgery to Settings Update

The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to missing or incorrect nonce validation on the ark_rp_options_page function. This makes it possible for unauthenticated attackers to modify the plugin's configuration settings via a …

📅 Published: Dec. 5, 2025, 7:26 a.m. 🔄 Last Modified: April 8, 2026, 6:23 p.m.

7.5

CVSS3.1

CVE-2025-12850 - My auctions allegro <= 3.6.32 - Unauthenticated SQL Injection via auction_id

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 3.6.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible f…

📅 Published: Dec. 5, 2025, 6:43 a.m. 🔄 Last Modified: April 8, 2026, 5:27 p.m.
Total resulsts: 344154
Page 2308 of 34,416
« previous page » next page
Filters