4.7

CVSS3.1

CVE-2025-14451 - Solutions Ad Manager <= 1.0.0 - Unauthenticated Open Redirect via 'sam-redirect-to' Parameter

The Solutions Ad Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.0. This is due to insufficient validation on the redirect URL supplied via the 'sam-redirect-to' parameter. This makes it possible for unauthenticated attackers to redirect users t…

📅 Published: Dec. 13, 2025, 4:31 a.m. 🔄 Last Modified: April 21, 2026, 5:15 p.m.

3.7

CVSS3.1

CVE-2025-9218 - rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthentica…

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers…

📅 Published: Dec. 13, 2025, 4:31 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-14288 - Gallery Blocks with Lightbox <= 3.3.0 - Missing Authorization to Authenticated (Contributor+) Plugi…

The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to unauthorized modification of plugin settings in all versions up to, and including, 3.3.0. This is due to the plugin using the `edit_pos…

📅 Published: Dec. 13, 2025, 4:31 a.m. 🔄 Last Modified: April 21, 2026, 5:15 p.m.

6.4

CVSS3.1

CVE-2025-13705 - Custom Frames <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Short…

The Custom Frames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter of the 'customframe' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi…

📅 Published: Dec. 13, 2025, 4:31 a.m. 🔄 Last Modified: April 21, 2026, 5:15 p.m.

8.8

CVSS3.1

CVE-2025-14476 - Doubly <= 1.0.46 - Authenticated (Subscriber+) PHP Object Injection via ZIP File Import

The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.46 via deserialization of untrusted input from the content.txt file within uploaded ZIP archives. This makes it possible for authenticated attacker…

📅 Published: Dec. 13, 2025, 4:31 a.m. 🔄 Last Modified: April 22, 2026, 12:15 a.m.

8.1

CVSS3.1

CVE-2025-14475 - Extensive VC Addons for WPBakery page builder <= 1.9.1 - Unauthenticated Local File Inclusion via '…

The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.1 via the `extensive_vc_get_module_template_part` function. This is due to insufficient path normalization and validation of the user-supplied `shor…

📅 Published: Dec. 13, 2025, 4:31 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2025-14462 - Lucky Draw Contests <= 4.2 - Cross-Site Request Forgery to Plugin Settings Update

The Lucky Draw Contests plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation in misc-settings.php. This makes it possible for unauthenticated attackers to update plugin settings via a forged …

📅 Published: Dec. 13, 2025, 4:31 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

6.4

CVSS3.1

CVE-2025-11376 - Colibri Page Builder <= 1.0.335 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe…

📅 Published: Dec. 13, 2025, 4:31 a.m. 🔄 Last Modified: April 22, 2026, 12:15 p.m.

8.8

CVSS3.1

CVE-2025-13094 - WP3D Model Import Viewer <= 1.0.7 - Authenticated (Contributor+) Arbitrary File Upload

The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_file() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Author-level access and above, to …

📅 Published: Dec. 13, 2025, 4:31 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-14447 - AnnunciFunebri Impresa <= 4.7.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Pl…

The AnnunciFunebri Impresa plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the annfu_reset_options() function in all versions up to, and including, 4.7.0. This makes it possible for authenticated attackers, with Subscriber-level access an…

📅 Published: Dec. 13, 2025, 4:31 a.m. 🔄 Last Modified: April 22, 2026, 4:15 p.m.
Total resulsts: 349182
Page 2624 of 34,919
« previous page » next page
Filters