4.3

CVSS3.1

CVE-2025-14392 - Simple Theme Changer <= 1.0. - Missing Authorization to Plugin Settings Update via AJAX Actions

The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_theme_admin, display_method_admin, and set_change_theme_button_name actions actions in all versions up to, and including, 1.0. This makes it possible for au…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

6.4

CVSS3.1

CVE-2025-14032 - Bold Timeline Lite <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' …

The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in the 'bold_timeline_group' shortcode in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated …

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

6.4

CVSS3.1

CVE-2025-13969 - Reviews Sorted <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'space' Shor…

The Reviews Sorted plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'space' parameter of the [reviews-slider] shortcode in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2025-14161 - Truefy Embed <= 1.1.0 - Cross-Site Request Forgery to 'truefy_embed_options_update' Settings Update

The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the 'truefy_embed_options_update' settings update action. This makes it possible for unauthenticated attackers to update the plug…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2025-14354 - Resource Library for Logged In Users <= 1.5 - Cross-Site Request Forgery to Multiple Administrative…

The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various …

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2025-14165 - Kirim.Email WooCommerce Integration <= 1.2.9 - Cross-Site Request Forgery to Settings Update

The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9. This is due to missing nonce validation on the plugin's settings page. This makes it possible for unauthenticated attackers to modify the plugin's AP…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 12:30 a.m.

6.4

CVSS3.1

CVE-2025-13846 - Easy Map Creator <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode …

The Easy Map Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access …

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2025-13363 - IMAQ Core <= 1.2.1 - Cross-Site Request Forgery to URL Structure Update

The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the URL structure settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's URL str…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2025-12783 - Premmerce Brands for WooCommerce <= 1.2.13 - Missing Authorization To Authenticated (Subscriber+) B…

The Premmerce Brands for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveBrandsSettings function in all versions up to, and including, 1.2.13. This makes it possible for authenticated attackers, with Subscriber-level a…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

8.1

CVSS3.1

CVE-2025-14044 - Visitor Logic Lite <= 1.0.3 - Unauthenticated PHP Object Injection via 'lpblocks' Cookie

The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.3 via deserialization of untrusted input from the `lpblocks` cookie. This is due to the `lp_track()` function passing unsanitized cookie data directly to the `unserialize()` f…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.
Total resulsts: 346506
Page 2378 of 34,651
« previous page » next page
Filters