6.4

CVSS3.1

CVE-2025-13656 - Cute News Ticker <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shor…

The Cute News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 22, 2026, 12:30 a.m.

6.4

CVSS3.1

CVE-2025-13899 - TR Timthumb <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attri…

The TR Timthumb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and ab…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 5:45 p.m.

5.4

CVSS3.1

CVE-2025-13308 - Application Passwords <= 0.1.3 - Reflected Cross-Site Scripting via reject_url

The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' parameter in all versions up to, and including, 0.1.3. This is due to insufficient input sanitization and output escaping on user supplied URLs, which allows javascript: URI schemes t…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 22, 2026, 4 a.m.

5.3

CVSS3.1

CVE-2025-13666 - Helloprint <= 2.1.2 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification

The Helloprint plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.2. This is due to the plugin registering a public REST API endpoint without implementing authorization checks to verify request authenticity. This makes it possible for unauthenticated a…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 5:45 p.m.

4.3

CVSS3.1

CVE-2025-13629 - WP Landing Page <= 0.9.3 - Cross-Site Request Forgery to Arbitrary Post Meta Update

The WP Landing Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing nonce validation on the 'wplp_api_update_text' function. This makes it possible for unauthenticated attackers to update arbitrary post meta via a …

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 22, 2026, 12:30 a.m.

9.8

CVSS3.1

CVE-2025-12673 - Flex QR Code Generator <= 1.2.7 - Unauthenticated Arbitrary File Upload

The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_qr_code() function in all versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected si…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 5:45 p.m.

5.3

CVSS3.1

CVE-2025-12720 - g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the handle_enqueue_only() function in all versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to delete arbitrary pro…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 21, 2026, 5:45 p.m.

4.3

CVSS3.1

CVE-2025-12574 - Listar – Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authe…

The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the '/wp-json/listar/v1/place/delete' REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for authenti…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 22, 2026, 4 a.m.

5.3

CVSS3.1

CVE-2025-12721 - g-FFL Cockpit <= 1.7.1 - Missing Authorization to Unauthenticated Information Exposure

The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract information about the serve…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-13896 - Social Feed Gallery Portfolio <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [igp-wp] shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke…

📅 Published: Dec. 6, 2025, 5:49 a.m. 🔄 Last Modified: April 22, 2026, 9 p.m.
Total resulsts: 349182
Page 2797 of 34,919
« previous page » next page
Filters