6.1

CVSS3.1

CVE-2025-13621 - dream gallery <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsm…

The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'dreampluginsmain' AJAX action. This makes it possible for unauthenticated attackers to update the plugin's setti…

📅 Published: Dec. 5, 2025, 5:31 a.m. 🔄 Last Modified: April 8, 2026, 4:47 p.m.

4.3

CVSS3.1

CVE-2025-12165 - Webcake – Landing Page Builder <= 1.1 - Missing Authorization to Authenticated (Subscriber+) Settin…

The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'webcake_save_config' AJAX endpoint in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-leve…

📅 Published: Dec. 5, 2025, 5:31 a.m. 🔄 Last Modified: April 8, 2026, 6:23 p.m.

6.4

CVSS3.1

CVE-2025-12163 - Omnipress <= 1.6.5 - Authenticated (Author+) Stored Cross-Site Scripting

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inj…

📅 Published: Dec. 5, 2025, 5:31 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

6.1

CVSS3.1

CVE-2025-13512 - CoSign Single Signon <= 0.3.1 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The CoSign Single Signon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje…

📅 Published: Dec. 5, 2025, 5:31 a.m. 🔄 Last Modified: April 8, 2026, 4:34 p.m.

4.4

CVSS3.1

CVE-2025-12124 - FitVids for WordPress <= 4.0.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permiss…

📅 Published: Dec. 5, 2025, 5:31 a.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.

4.3

CVSS3.1

CVE-2025-13144 - ContentStudio <= 1.3.7 - Cross-Site Request Forgery to Settings Update

The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or insufficient nonce validation on the add_cstu_settings function. This makes it possible for unauthenticated attackers to modify plugin settings v…

📅 Published: Dec. 5, 2025, 5:31 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

5.3

CVSS3.1

CVE-2025-13312 - CRM Memberships <= 2.5 - Missing Authorization to Unauthenticated 'ntzcrm_add_new_tag' AJAX Action

The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_new_tag' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to create arbitrary membership tags a…

📅 Published: Dec. 5, 2025, 4:29 a.m. 🔄 Last Modified: April 8, 2026, 5:33 p.m.

5.3

CVSS3.1

CVE-2025-13006 - SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via several unprotected /wp-json/surveyfunnel/v2/ REST API endpoints. This makes it possible for unauthenticated attackers to extract sensi…

📅 Published: Dec. 5, 2025, 4:29 a.m. 🔄 Last Modified: April 8, 2026, 5:33 p.m.

9.8

CVSS3.1

CVE-2025-13313 - CRM Memberships <= 2.6 - Missing Authorization to Privilege Escalation via Unauthenticated Password…

The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is due to missing authorization and authentication checks on the `ntzcrm_changepassword` AJAX action. This makes it possible for unauthenticated attacker…

📅 Published: Dec. 5, 2025, 4:29 a.m. 🔄 Last Modified: April 8, 2026, 7:23 p.m.

4.3

CVSS3.1

CVE-2025-13362 - Norby AI <= 1.0.3 - Cross-Site Request Forgery to Settings Update

The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's settings and inject ma…

📅 Published: Dec. 5, 2025, 4:29 a.m. 🔄 Last Modified: April 8, 2026, 5:02 p.m.
Total resulsts: 344130
Page 2309 of 34,413
« previous page » next page
Filters