6.4

CVSS3.1

CVE-2025-13906 - WP Flot <= 0.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The WP Flot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linechart' shortcode in all versions up to, and including, 0.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 20, 2026, 9:45 p.m.

6.1

CVSS3.1

CVE-2025-13988 - 评论小秘书 <= 1.3.2 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The 评论小秘书 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.3.2. This is due to insufficient input sanitization and output escaping on the `$_SERVER['PHP_SELF']` variable in the plugin's settings page…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 20, 2026, 9:45 p.m.

6.4

CVSS3.1

CVE-2025-13966 - Paypal Payment Shortcode <= 1.01 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bu…

The Paypal Payment Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttom_image' parameter of the [paypal-shortcode] shortcode in all versions up to, and including, 1.01 due to insufficient input sanitization and output escaping. This makes it possible for authe…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 1 a.m.

6.4

CVSS3.1

CVE-2025-13961 - Data Visualizer <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Att…

The Data Visualizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'visualize' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 1 a.m.

6.4

CVSS3.1

CVE-2025-13884 - Hide Email Address <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode …

The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inline_css' parameter in the `bg-hide-email-address` shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This mak…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 20, 2026, 9:45 p.m.

4.4

CVSS3.1

CVE-2025-14035 - DebateMaster <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Color Option…

The DebateMaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color options in the plugin settings in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administra…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

6.4

CVSS3.1

CVE-2025-13840 - BUKAZU Search widget <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'short…

The BUKAZU Search widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode' parameter of the 'bukazu_search' shortcode in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

6.4

CVSS3.1

CVE-2025-13960 - GPXpress <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The GPXpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gpxpress' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, …

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 1 a.m.

6.8

CVSS3.1

CVE-2025-13320 - WP User Manager <= 2.9.12 - Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_a…

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_inpu…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 21, 2026, 5:30 p.m.

5.3

CVSS3.1

CVE-2025-13440 - Premmerce Wishlist for WooCommerce <= 1.1.10 - Missing Authorization to Authenticated (Subscriber+)…

The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.10. This is due to a missing capability check on the deleteWishlist() function. This makes it possible for authenticated attackers, with Subscriber-level acce…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: April 22, 2026, 12:30 a.m.
Total resulsts: 349182
Page 2644 of 34,919
« previous page » next page
Filters