5.3

CVSS3.1

CVE-2025-62147 - WordPress Realbig plugin <= 1.1.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in nikmelnik Realbig realbig-media allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Realbig: from n/a through <= 1.1.3.

πŸ“… Published: Dec. 31, 2025, 3:01 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.3

CVSS3.1

CVE-2025-62081 - WordPress Live Shopping & Shoppable Videos For WooCommerce plugin <= 2.2.0 - Broken Access Control …

Missing Authorization vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2…

πŸ“… Published: Dec. 31, 2025, 3 p.m. πŸ”„ Last Modified: April 28, 2026, 4:14 p.m.

5.3

CVSS3.1

CVE-2025-63053 - WordPress Master Addons for Elementor plugin <= 2.0.9.9.4 - Insecure Direct Object References (IDOR…

Authorization Bypass Through User-Controlled Key vulnerability in Liton Arefin Master Addons for Elementor master-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Master Addons for Elementor: from n/a through <= 2.0.9.9.4.

πŸ“… Published: Dec. 31, 2025, 2:59 p.m. πŸ”„ Last Modified: April 23, 2026, 3:35 p.m.

5.3

CVSS3.1

CVE-2025-63001 - WordPress Hotel Booking plugin <= 3.8 - Broken Access Control vulnerability

Missing Authorization vulnerability in nicdark Hotel Booking nd-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Booking: from n/a through <= 3.8.

πŸ“… Published: Dec. 31, 2025, 2:56 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.3

CVSS3.1

CVE-2025-49349 - WordPress Reuters Direct plugin <= 3.0.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Reuters News Agency Reuters Direct reuters-direct allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reuters Direct: from n/a through <= 3.0.0.

πŸ“… Published: Dec. 31, 2025, 2:48 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

5.4

CVSS3.1

CVE-2025-62098 - WordPress Portfolio Gallery plugin <= 1.4.8 - Broken Access Control vulnerability

Missing Authorization vulnerability in totalsoft Portfolio Gallery gallery-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery: from n/a through <= 1.4.8.

πŸ“… Published: Dec. 31, 2025, 2:47 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.4

CVSS3.1

CVE-2025-62091 - WordPress Serial Codes Generator and Validator with WooCommerce Support plugin <= 2.8.2 - Broken Ac…

Missing Authorization vulnerability in Vollstart Serial Codes Generator and Validator with WooCommerce Support serial-codes-generator-and-validator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Serial Codes Generator and Validator with WooCommerce Suppor…

πŸ“… Published: Dec. 31, 2025, 2:19 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.4

CVSS3.1

CVE-2025-62108 - WordPress Add Custom Codes plugin <= 4.80 - Broken Access Control vulnerability

Missing Authorization vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Add Custom Codes: from n/a through <= 4.80.

πŸ“… Published: Dec. 31, 2025, 2:18 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.4

CVSS3.1

CVE-2025-62888 - WordPress WP Attachments plugin <= 5.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Marco Milesi WP Attachments wp-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Attachments: from n/a through <= 5.2.

πŸ“… Published: Dec. 31, 2025, 2:17 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.4

CVSS3.1

CVE-2025-62117 - WordPress EasyIndex plugin <= 1.1.1704 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Jayce53 EasyIndex easyindex allows Cross Site Request Forgery.This issue affects EasyIndex: from n/a through <= 1.1.1704.

πŸ“… Published: Dec. 31, 2025, 1:56 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.
Total resulsts: 349182
Page 2327 of 34,919
Β« previous page Β» next page
Filters