9.1

CVSS3.1

CVE-2025-62892 - WordPress Sunshine Photo Cart plugin <= 3.5.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.3.

๐Ÿ“… Published: Oct. 27, 2025, 1:33 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:09 p.m.

8.8

CVSS3.1

CVE-2025-62891 - WordPress Off-Canvas Sidebars & Menus (Slidebars) plugin <= 0.5.8.5 - Cross Site Request Forgery (Cโ€ฆ

Cross-Site Request Forgery (CSRF) vulnerability in Jory Hogeveen Off-Canvas Sidebars & Menus (Slidebars) off-canvas-sidebars allows Cross Site Request Forgery.This issue affects Off-Canvas Sidebars & Menus (Slidebars): from n/a through <= 0.5.8.5.

๐Ÿ“… Published: Oct. 27, 2025, 1:33 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:09 p.m.

8.8

CVSS3.1

CVE-2025-62890 - WordPress Premmerce Brands for WooCommerce plugin <= 1.2.13 - Cross Site Request Forgery (CSRF) vulโ€ฆ

Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Brands for WooCommerce premmerce-woocommerce-brands allows Cross Site Request Forgery.This issue affects Premmerce Brands for WooCommerce: from n/a through <= 1.2.13.

๐Ÿ“… Published: Oct. 27, 2025, 1:33 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:09 p.m.

8.8

CVSS3.1

CVE-2025-62889 - WordPress King Addons for Elementor plugin <= 51.1.61 - Broken Access Control vulnerability

Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects King Addons for Elementor: from n/a through <= 51.1.61.

๐Ÿ“… Published: Oct. 27, 2025, 1:33 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 3:18 p.m.

5.4

CVSS3.1

CVE-2025-62887 - WordPress King Addons for Elementor plugin <= 51.1.61 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KingAddons.com King Addons for Elementor king-addons allows DOM-Based XSS.This issue affects King Addons for Elementor: from n/a through <= 51.1.61.

๐Ÿ“… Published: Oct. 27, 2025, 1:33 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 3:18 p.m.

8.8

CVSS3.1

CVE-2025-62886 - WordPress Pricing Table builder plugin <= 1.5.3 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored XSS.This issue affects Pricing Table builder: from n/a through <= 1.5.3.

๐Ÿ“… Published: Oct. 27, 2025, 1:33 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 3:18 p.m.

6.5

CVSS3.1

CVE-2025-62885 - WordPress WP VR plugin <= 8.5.48 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpvr allows DOM-Based XSS.This issue affects WP VR: from n/a through <= 8.5.48.

๐Ÿ“… Published: Oct. 27, 2025, 1:33 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 3:18 p.m.

5.3

CVSS3.1

CVE-2025-62884 - WordPress Coupon Affiliates plugin <= 7.2.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coupon Affiliates: from n/a through <= 7.2.0.

๐Ÿ“… Published: Oct. 27, 2025, 1:33 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 3:18 p.m.

4.3

CVSS3.1

CVE-2025-62883 - WordPress Premmerce User Roles plugin <= 1.0.13 - Broken Access Control vulnerability

Missing Authorization vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce User Roles: from n/a through <= 1.0.13.

๐Ÿ“… Published: Oct. 27, 2025, 1:33 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:09 p.m.

4.3

CVSS3.1

CVE-2025-62882 - WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

๐Ÿ“… Published: Oct. 27, 2025, 1:33 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:09 p.m.
Total resulsts: 343996
Page 2760 of 34,400
ยซ previous page ยป next page
Filters