6.4

CVSS3.1

CVE-2025-13989 - WP Dropzone <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'callback' Shor…

The WP Dropzone plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callback' shortcode attribute in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on user-supplied 'callback' attributes, which are evaluated as Jav…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 9 p.m.

6.1

CVSS3.1

CVE-2025-14125 - Complag <= 1.0.2 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Complag plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 4:30 p.m.

6.4

CVSS3.1

CVE-2025-14393 - Wpik WordPress Basic Ajax Form <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 4:30 p.m.

6.4

CVSS3.1

CVE-2025-14143 - Ayo Shortcodes <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortc…

The Ayo Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' parameter of the ayo_action shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with C…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 4:30 p.m.

4.9

CVSS3.1

CVE-2025-13972 - WatchTowerHQ <= 3.16.0 - Authenticated (Administrator+) Arbitrary File Read via 'wht_download_big_o…

The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' parameter in all versions up to, and including, 3.16.0. This is due to insufficient path validation in the handle_big_object_download_request function. This makes it possible for auth…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 4:30 p.m.

5.4

CVSS3.1

CVE-2025-14064 - BuddyTask <= 1.3.0 - Missing Authorization to Authenticated (Subscriber+) Cross-Group Task Board Ac…

The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple AJAX endpoints in all versions up to, and including, 1.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to v…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 4:30 p.m.

4.4

CVSS3.1

CVE-2025-14467 - WP Job Portal <= 2.4.4 - Authenticated (Editor+) Stored Cross-Site Scripting via Job Description Fi…

The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.4. This is due to the plugin explicitly whitelisting the `<script>` tag in its `WPJOBPORTAL_ALLOWED_TAGS` configuration and using insufficient input sanitization when saving…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 9 p.m.

6.4

CVSS3.1

CVE-2025-13889 - Simple Nivo Slider <= 0.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcod…

The Simple Nivo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode parameter in all versions up to, and including, 0.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-leve…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 4:30 p.m.

4.3

CVSS3.1

CVE-2025-14170 - Vimeo SimpleGallery <= 0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin …

The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 0.2. This is due to missing authorization checks on the `vimeogallery_admin` function hooked to `admin_menu`. This makes it possible for authenticated attackers, with Subscriber…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 4:30 p.m.

6.4

CVSS3.1

CVE-2025-13866 - Flow-Flow Social Feed Stream 3.0.0 - 4.7.5 - Missing Authorization to Authenticated (Subscriber+) S…

The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the flow_flow_social_auth AJAX action in versions 3.0.0 to 4.7.5. This makes it possible for authenticated attackers, with Subscriber-level access and above,…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346514
Page 2381 of 34,652
« previous page » next page
Filters