6.5

CVSS3.1

CVE-2025-11372 - LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Ta…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This is due to missing capability checks on the Admin Tools REST endpoints which are registered with permission_callback set to __return_true. This makes i…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:25 p.m.

9.8

CVSS3.1

CVE-2025-11391 - PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated Arbitrary File U…

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image cropper functionality in all versions up to, and including, 33.0.15. This makes it possible for unauthenticated attackers to upload…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:24 p.m.

6.4

CVSS3.1

CVE-2025-11270 - Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 5.7.1 - Authenticated …

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

4.3

CVSS3.1

CVE-2025-11519 - Image optimization service by Optimole <= 4.1.0 - Insecure Direct Object Reference to Authenticated…

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the /wp-json/optml/v1/move_image REST API endpoint due to missing validation on a user c…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:09 p.m.

4.3

CVSS3.1

CVE-2025-11510 - FileBird <= 6.4.9 - Improper Authorization to Authenticated (Author+) Settings Reset

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /filebird/v1/fb-wipe-clear-all-data function in all versions up to, and including, 6.4.9. This makes it possible for authent…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 4:56 p.m.

6.4

CVSS3.1

CVE-2025-9562 - Redirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 4:55 p.m.

5.3

CVSS3.1

CVE-2025-11703 - WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated att…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 4:52 p.m.

6.4

CVSS3.1

CVE-2025-10006 - WPBakery Page Builder <= 8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, 8.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 4:51 p.m.

4.9

CVSS3.1

CVE-2025-10187 - GSpeech TTS – WordPress Text To Speech Plugin <= 3.17.13 - Authenticated (Admin+) SQL injection

The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' parameter in all versions up to, and including, 3.17.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 4:50 p.m.

5.3

CVSS3.1

CVE-2025-11741 - WPC Smart Quick View for WooCommerce <= 4.2.5 - Insecure Direct Object Reference to Unauthenticated…

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attacke…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.
Total resulsts: 343948
Page 2851 of 34,395
« previous page » next page
Filters