5.4

CVSS3.1

CVE-2025-62017 - WordPress Kallyas theme <= 4.22.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in hogash Kallyas kallyas.This issue affects Kallyas: from n/a through <= 4.22.0.

๐Ÿ“… Published: Nov. 6, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 6, 2025, 8:38 p.m.

0.0

CVE-2025-62016 - WordPress Kallyas theme <= 4.22.0 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in hogash Kallyas kallyas.This issue affects Kallyas: from n/a through <= 4.22.0.

๐Ÿ“… Published: Nov. 6, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 6, 2025, 8:19 p.m.

0.0

CVE-2025-62014 - WordPress ITok theme <= 1.1.42 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme ITok itok.This issue affects ITok: from n/a through <= 1.1.42.

๐Ÿ“… Published: Nov. 6, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 6, 2025, 8:19 p.m.

6.5

CVSS3.1

CVE-2025-62012 - WordPress TheGem (Elementor) theme <= 5.10.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor) thegem-elementor.This issue affects TheGem (Elementor): from n/a through <= 5.10.5.

๐Ÿ“… Published: Nov. 6, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 3:15 p.m.

6.5

CVSS3.1

CVE-2025-62011 - WordPress TheGem theme <= 5.10.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem thegem.This issue affects TheGem: from n/a through <= 5.10.5.

๐Ÿ“… Published: Nov. 6, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 3:15 p.m.

8.1

CVSS3.1

CVE-2025-62010 - WordPress Famita theme <= 1.54 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Famita famita allows PHP Local File Inclusion.This issue affects Famita: from n/a through <= 1.54.

๐Ÿ“… Published: Nov. 6, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 3:15 p.m.

7.5

CVSS3.1

CVE-2025-60248 - WordPress WPC Product Options for WooCommerce plugin <= 1.8.6 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPClever WPC Product Options for WooCommerce wpc-product-options allows PHP Local File Inclusion.This issue affects WPC Product Options for WooCommerce: from n/a through <= 1.8.6.

๐Ÿ“… Published: Nov. 6, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 3:15 p.m.

6.5

CVSS3.1

CVE-2025-60247 - WordPress Bux Woocommerce plugin <= 1.2.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Bux Bux Woocommerce bux-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bux Woocommerce: from n/a through <= 1.2.3.

๐Ÿ“… Published: Nov. 6, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 3:15 p.m.

0.0

CVE-2025-60245 - WordPress WP User Manager plugin <= 2.9.12 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12.

๐Ÿ“… Published: Nov. 6, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 6, 2025, 8:38 p.m.

0.0

CVE-2025-60244 - WordPress TableOn plugin <= 1.0.4.2 - Content Injection vulnerability

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RealMag777 TableOn posts-table-filterable allows Code Injection.This issue affects TableOn: from n/a through <= 1.0.4.2.

๐Ÿ“… Published: Nov. 6, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:54 a.m.
Total resulsts: 317402
Page 24 of 31,741
ยซ previous page ยป next page
Filters