5.3

CVSS3.1

CVE-2025-68556 - WordPress HAPPY plugin <= 1.0.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.9.

๐Ÿ“… Published: Dec. 23, 2025, 11:44 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:36 p.m.

4.3

CVSS3.1

CVE-2025-68557 - WordPress Chakra test plugin <= 1.0.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Vikas Ratudi Chakra test chakra-test allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chakra test: from n/a through <= 1.0.1.

๐Ÿ“… Published: Dec. 23, 2025, 11:43 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:36 p.m.

6.5

CVSS3.1

CVE-2025-68559 - WordPress TheGem Theme Elements (for Elementor) plugin <= 5.10.5.1 - Cross Site Scripting (XSS) vulโ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.10.5.1.

๐Ÿ“… Published: Dec. 23, 2025, 11:37 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:36 p.m.

7.5

CVSS3.1

CVE-2025-68560 - WordPress TheGem Theme Elements (for Elementor) plugin <= 5.10.5.1 - Local File Inclusion vulnerabiโ€ฆ

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.10.5.1.

๐Ÿ“… Published: Dec. 23, 2025, 11:36 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:36 p.m.

7.6

CVSS3.1

CVE-2025-68561 - WordPress AutomatorWP plugin <= 5.2.4 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows SQL Injection.This issue affects AutomatorWP: from n/a through <= 5.2.4.

๐Ÿ“… Published: Dec. 23, 2025, 11:34 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:36 p.m.

8.8

CVSS3.1

CVE-2025-59886 -

Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device executing privileged user commands.ย As cybersecurity standards continue to evolve and to meet our requirements today, Eaton has decided to discontโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 11:31 a.m. ๐Ÿ”„ Last Modified: Feb. 18, 2026, 2:39 p.m.

6.4

CVSS3.1

CVE-2025-14635 - Happy Addons for Elementor <= 3.20.3 - Authenticated (Contributor+) Stored Cross-Site Scripting viaโ€ฆ

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Coโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 11:13 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 4 p.m.

6.4

CVSS3.1

CVE-2025-14000 - Membership Plugin โ€“ Restrict Content <= 3.2.15 - Authenticated (Contributor+) Stored Cross-Site Scrโ€ฆ

The Membership Plugin โ€“ Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping on user supplied attributes. โ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 11:13 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 4:15 p.m.

9.8

CVSS3.1

CVE-2025-14388 - PhastPress <= 3.7 - Unauthenticated Arbitrary File Read via Null Byte Injection

The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including, 3.7. This is due to a discrepancy between the extension validation in `getExtensionForURL()` which operates on URL-decoded paths, and `appendNormaliโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 9:20 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 9:30 p.m.

8.1

CVSS3.1

CVE-2025-12934 - Beaver Builder โ€“ WordPress Page Builder <= 2.9.4.1 - Missing Authorization to Authenticated (Subscrโ€ฆ

The Beaver Builder โ€“ WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'duplicate_wpml_layout' function in all versions up to, and including, 2.9.4.1. This makes it possible for authenticated attackers,โ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 9:20 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 5 p.m.
Total resulsts: 349182
Page 2470 of 34,919
ยซ previous page ยป next page
Filters