8.8

CVSS3.1

CVE-2025-13065 - Starter Templates <= 4.4.41 - Authenticated (Author+) Arbitrary File Upload via WXR Upload Bypass

The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This…

📅 Published: Dec. 6, 2025, 9:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-12966 - All-in-One Video Gallery 4.5.4 - 4.5.7 – Authenticated (Author+) Arbitrary File Upload via Import Z…

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the resolve_import_directory() function in versions 4.5.4 to 4.5.7. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbi…

📅 Published: Dec. 6, 2025, 9:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-12499 - Rich Shortcodes for Google Reviews <= 6.8 - Unauthenticated Stored Cross-Site Scripting via Google …

The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contents of a Google Review in all versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to …

📅 Published: Dec. 6, 2025, 7:29 a.m. 🔄 Last Modified: April 21, 2026, 1 a.m.

9.6

CVSS3.1

CVE-2025-13377 - 10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_…

The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the get_cache_dir_for_page_from_url() function in all versions up to, and including, 2.32.7. This makes it possibl…

📅 Published: Dec. 6, 2025, 6:39 a.m. 🔄 Last Modified: April 21, 2026, 1 a.m.

5.3

CVSS3.1

CVE-2025-13748 - Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tamperin…

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user controlled key within t…

📅 Published: Dec. 6, 2025, 6:39 a.m. 🔄 Last Modified: April 20, 2026, 9:45 p.m.

5.3

CVSS3.1

CVE-2025-13358 - Accessiy By CodeConfig Accessibility <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+…

The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing authorization checks in versions up to, and including, 1.0.0. This is due to the plugin not performing capability checks in the `Settings::createPage()` function. This makes it p…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 1:15 a.m.

4.3

CVSS3.1

CVE-2025-13309 - Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters <= 1…

The Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. Thi…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 1:15 a.m.

6.1

CVSS3.1

CVE-2025-13894 - CSV Sumotto <= 1.0 - Reflected Cross-Site Scripting

The CSV Sumotto plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 20, 2026, 9:45 p.m.

4.3

CVSS3.1

CVE-2025-12091 - Search, Filters & Merchandising for WooCommerce <= 3.0.67 - Missing Authorization to Authenticated …

The Search, Filters & Merchandising for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcis_save_email' endpoint in all versions up to, and including, 3.0.67. This makes it possible for authenticated attackers, with Subs…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-13857 - Yet Another WebClap for WordPress <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The Yet Another WebClap for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter of the webclap_button shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authentic…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346002
Page 2478 of 34,601
« previous page » next page
Filters