4.3

CVSS3.1

CVE-2025-14160 - Upcoming for Calendly <= 1.2.4 - Cross-Site Request Forgery to Settings Update

The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's Calendly …

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 20, 2026, 9:30 p.m.

6.4

CVSS3.1

CVE-2025-13963 - FX Currency Converter <= 0.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Short…

The FX Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fxcc_convert' shortcode in all versions up to, and including, 0.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

6.4

CVSS3.1

CVE-2025-13962 - Divelogs Widget <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Att…

The Divelogs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'latestdive' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2025-13987 - Purchase and Expense Manager <= 1.1.2 - Cross-Site Request Forgery to Arbitrary Purchase Record Del…

The Purchase and Expense Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing nonce validation on the 'sup_pt_handle_deletion' function. This makes it possible for unauthenticated attackers to delete arbitrary p…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 20, 2026, 9:30 p.m.

5.3

CVSS3.1

CVE-2025-13314 - Product Filtering by Categories, Tags, Price Range for WooCommerce <= 1.1.6 - Missing Authorization…

The Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.1.6 due to a missing capability check on the 'filter_save_settings' and 'add_filter_options' AJAX acti…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 1 a.m.

6.4

CVSS3.1

CVE-2025-13885 - Zenost Shortcodes <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode A…

The Zenost Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' and 'target' parameters in the `button` shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 20, 2026, 9:30 p.m.

4.3

CVSS3.1

CVE-2025-14062 - Animated Pixel Marquee Creator <= 1.0.0 - Cross-Site Request Forgery via 'marquee' Parameter

The Animated Pixel Marquee Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery via the 'marquee' parameter in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the marquee deletion function. This makes it possible for unauthenticated attackers…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 20, 2026, 9:30 p.m.

9.8

CVSS3.1

CVE-2025-12963 - LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart <= 1.2.29 - Missin…

The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.29. This is due to the plugin not properly validating a user's identity via the 'wp-json/laz…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

6.1

CVSS3.1

CVE-2025-14132 - Category Dropdown List <= 1.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Category Dropdown List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injec…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 1 a.m.

4.4

CVSS3.1

CVE-2025-13971 - TWW Protein Calculator <= 1.0.24 - Authenticated (Administrator+) Stored Cross-Site Scripting via '…

The TWW Protein Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Header' setting in all versions up to, and including, 1.0.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 1 a.m.
Total resulsts: 349182
Page 2643 of 34,919
« previous page » next page
Filters