6.4

CVSS3.1

CVE-2025-13843 - VigLink SpotLight By ShortCode <= 1.0.a - Authenticated (Contributor+) Stored Cross-Site Scripting …

The VigLink SpotLight By ShortCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'float' parameter of the 'spotlight' shortcode in all versions up to, and including, 1.0.a due to insufficient input sanitization and output escaping on user supplied attributes. This makes …

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 21, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2025-14391 - Simple Theme Changer <= 1.0 - Cross-Site Request Forgery to Arbitrary Theme Switcher Configuration …

The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted th…

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 20, 2026, 9:30 p.m.

4.3

CVSS3.1

CVE-2025-13366 - Rabbit Hole <= 1.1 - Cross-Site Request Forgery to Settings Reset

The Rabbit Hole plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the plugin's reset functionality. This makes it possible for unauthenticated attackers to reset the plugin's settings v…

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 21, 2026, 1 a.m.

6.4

CVSS3.1

CVE-2025-13747 - NewStatPress <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode function in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 20, 2026, 9:30 p.m.

6.4

CVSS3.1

CVE-2025-13850 - LS Google Map Router <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortc…

The LS Google Map Router plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'map_type' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level …

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 21, 2026, 1 a.m.

6.1

CVSS3.1

CVE-2025-14137 - Simple AL Slider <= 1.2.10 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Simple AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a…

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 20, 2026, 9:30 p.m.

6.4

CVSS3.1

CVE-2025-12650 - Simple post listing <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Simple post listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_name' parameter in the postlist shortcode in all versions up to, and including, 0.2. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: April 21, 2026, 1 a.m.

6.1

CVSS3.1

CVE-2025-12834 - Accept Stripe Payments Using Contact Form 7 <= 3.1 - Reflected Cross-Site Scripting via failure_mes…

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failure_message' parameter in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attac…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: April 21, 2026, 1 a.m.

8.1

CVSS3.1

CVE-2025-13334 - Blaze Demo Importer 1.0.0 - 1.0.13 - Missing Authorization to Authenticated (Subscriber+) Database …

The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the "blaze_demo_importer_install_demo" function in all versions up to, and including, 1.0.13. This makes it possible for authenticated attackers, with su…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-12830 - Better Elementor Addons <= 1.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sli…

The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider widget in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: April 21, 2026, 1 a.m.
Total resulsts: 349182
Page 2642 of 34,919
Β« previous page Β» next page
Filters