7.2

CVSS3.1

CVE-2025-9343 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.4 - Unauthenticated Stored Cross-Site Sc…

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers …

📅 Published: Dec. 21, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 4:15 p.m.

6.9

CVSS4.0

CVE-2025-14990 - Campcodes Complete Online Beauty Parlor Management System view-appointment.php sql injection

A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unknown function of the file /admin/view-appointment.php. Performing a manipulation of the argument viewid results in sql injection. The attack may be initiated remotely. The exploit…

📅 Published: Dec. 21, 2025, 3:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 6:16 a.m.

7.4

CVSS3.1

CVE-2025-68644 -

Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanced authentication mechanism through a security update to all cloud instances.

📅 Published: Dec. 21, 2025, 3:01 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-12980 - Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.3 - Missing Authorizat…

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '/ultp/v2/get_dynamic_content/' REST API endpoint in all versions up to, and including, 5.0.3. This makes it possible …

📅 Published: Dec. 21, 2025, 2:20 a.m. 🔄 Last Modified: April 21, 2026, 12:45 a.m.

5.3

CVSS3.1

CVE-2025-14043 - Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation

The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization checks in all versions up to, and including, 1.0.1. This is due to the `create_item_permissions_check()` function unconditionally returning true, which bypasses authentication and …

📅 Published: Dec. 21, 2025, 2:20 a.m. 🔄 Last Modified: April 22, 2026, 12:15 a.m.

4.4

CVSS3.1

CVE-2025-14054 - WC Builder <= 1.2.0 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'heading_color'…

The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'heading_color' parameter (and multiple other styling parameters) of the `wpbforwpbakery_product_additional_information` shortcode in all versions up to, and including, 1…

📅 Published: Dec. 21, 2025, 2:20 a.m. 🔄 Last Modified: April 22, 2026, 12:15 a.m.

6.4

CVSS3.1

CVE-2025-13838 - WishSuite <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Sho…

The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the 'wishsuite_button' shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack…

📅 Published: Dec. 21, 2025, 2:20 a.m. 🔄 Last Modified: April 21, 2026, 5 p.m.

7.5

CVSS3.1

CVE-2025-14071 - Live Composer – Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) PHP Object I…

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 via deserialization of untrusted input in the dslc_module_posts_output shortcode. This makes it possible for authenticated attackers, with Contri…

📅 Published: Dec. 21, 2025, 2:20 a.m. 🔄 Last Modified: April 21, 2026, 5 p.m.

5.3

CVSS3.1

CVE-2025-14080 - Frontend Post Submission Manager Lite <= 1.2.5 - Missing Authorization to Unauthenticated Arbitrary…

The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.5. This is due to missing authorization checks on the post update functionality in the fpsml_form_process AJAX action. This makes it possible for unauthent…

📅 Published: Dec. 21, 2025, 2:20 a.m. 🔄 Last Modified: April 21, 2026, 5 p.m.

6.1

CVSS3.1

CVE-2025-11496 - Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.5 - Unauthenticated Stored Cros…

The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthen…

📅 Published: Dec. 21, 2025, 2:20 a.m. 🔄 Last Modified: April 22, 2026, 8:30 p.m.
Total resulsts: 349182
Page 2487 of 34,919
« previous page » next page
Filters