4.3

CVSS3.1

CVE-2025-68989 - WordPress Contact Form 7 Extension For Mailchimp plugin <= 0.9.68 - Sensitive Data Exposure vulnera…

Insertion of Sensitive Information Into Sent Data vulnerability in Renzo Johnson contact-form-7-mailchimp-extension contact-form-7-mailchimp-extension allows Retrieve Embedded Sensitive Data.This issue affects contact-form-7-mailchimp-extension: from n/a through <= 0.9.68.

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 24, 2026, 6:58 p.m.

5.3

CVSS3.1

CVE-2025-68988 - WordPress E-Invoice App Malaysia plugin <= 1.3.0 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia einvoiceapp-malaysia allows Retrieve Embedded Sensitive Data.This issue affects E-Invoice App Malaysia: from n/a through <= 1.3.0.

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 24, 2026, 6:58 p.m.

7.5

CVSS3.1

CVE-2025-68987 - WordPress Cinerama theme <= 2.9 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Cinerama cinerama allows PHP Local File Inclusion.This issue affects Cinerama: from n/a through <= 2.9.

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 24, 2026, 6:58 p.m.

7.5

CVSS3.1

CVE-2025-68985 - WordPress Aora theme <= 1.3.15 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP Local File Inclusion.This issue affects Aora: from n/a through <= 1.3.15.

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 24, 2026, 6:58 p.m.

7.5

CVSS3.1

CVE-2025-68984 - WordPress Puca theme <= 2.6.39 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Puca puca allows PHP Local File Inclusion.This issue affects Puca: from n/a through <= 2.6.39.

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 24, 2026, 6:58 p.m.

7.5

CVSS3.1

CVE-2025-68983 - WordPress Greenmart theme <= 4.2.11 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart greenmart allows PHP Local File Inclusion.This issue affects Greenmart: from n/a through <= 4.2.11.

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 24, 2026, 6:58 p.m.

5.3

CVSS3.1

CVE-2025-68982 - WordPress DesignThemes LMS Addon plugin <= 2.6 - Broken Access Control vulnerability

Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes LMS Addon: from n/a through <= 2.6.

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 24, 2026, 6:58 p.m.

5.3

CVSS3.1

CVE-2025-68981 - WordPress HomeFix Elementor Portfolio plugin <= 1.0.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HomeFix Elementor Portfolio: from n/a through <= 1.0.1.

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 24, 2026, 6:58 p.m.

5.3

CVSS3.1

CVE-2025-68980 - WordPress WeDesignTech Portfolio plugin <= 1.0.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in designthemes WeDesignTech Portfolio wedesigntech-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Portfolio: from n/a through <= 1.0.2.

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 24, 2026, 6:58 p.m.

5.3

CVSS3.1

CVE-2025-68979 - WordPress Google Calendar Events plugin <= 3.5.9 - Insecure Direct Object References (IDOR) vulnera…

Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-events allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Calendar Events: from n/a through <= 3.5.9.

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 24, 2026, 6:58 p.m.
Total resulsts: 349182
Page 2349 of 34,919
Β« previous page Β» next page
Filters