4.3

CVSS3.1

CVE-2025-13309 - Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters <= 1…

The Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. Thi…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 1:15 a.m.

6.1

CVSS3.1

CVE-2025-13894 - CSV Sumotto <= 1.0 - Reflected Cross-Site Scripting

The CSV Sumotto plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 20, 2026, 9:45 p.m.

4.3

CVSS3.1

CVE-2025-12091 - Search, Filters & Merchandising for WooCommerce <= 3.0.67 - Missing Authorization to Authenticated …

The Search, Filters & Merchandising for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcis_save_email' endpoint in all versions up to, and including, 3.0.67. This makes it possible for authenticated attackers, with Subs…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 5:45 p.m.

6.4

CVSS3.1

CVE-2025-13857 - Yet Another WebClap for WordPress <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The Yet Another WebClap for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter of the webclap_button shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authentic…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 5:45 p.m.

6.4

CVSS3.1

CVE-2025-13856 - Extra Post Images <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode A…

The Extra Post Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the extra-images shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 1:15 a.m.

6.4

CVSS3.1

CVE-2025-13863 - RevInsite <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribu…

The RevInsite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `token` parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abo…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 1:15 a.m.

6.4

CVSS3.1

CVE-2025-13907 - CSS3 Buttons <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attrib…

The CSS3 Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 5:45 p.m.

6.4

CVSS3.1

CVE-2025-12717 - List Attachments Shortcode <= 0.4.1a - Authenticated (Author+) Stored Cross-Site Scripting via list…

The List Attachments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_list' parameter in the [list-attachments] shortcode in all versions up to, and including, 0.4.1a due to insufficient input sanitization and output escaping. This makes it possible for au…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 1:15 a.m.

4.3

CVSS3.1

CVE-2025-12577 - Listar – Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authe…

The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/listar/v1/place/save' REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for au…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 22, 2026, 12:30 a.m.

6.4

CVSS3.1

CVE-2025-12715 - Canadian Nutrition Facts Label <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Canadian Nutrition Facts Label plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'percentage' field in the Nutrition Label custom post type in all versions up to, and including, 3.0 due to insufficient input sanitization and output escaping. This makes it possible for au…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 22, 2026, 4 a.m.
Total resulsts: 349182
Page 2796 of 34,919
« previous page » next page
Filters