4.4

CVSS3.1

CVE-2025-13311 - Just Highlight <= 1.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Highlight…

The Just Highlight plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Highlight Color' setting in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

📅 Published: Nov. 25, 2025, 7:28 a.m. 🔄 Last Modified: April 21, 2026, 1:30 a.m.

6.4

CVSS3.1

CVE-2025-12645 - Inline frame – Iframe <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortco…

The Inline frame – Iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedsite' shortcode in all versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat…

📅 Published: Nov. 25, 2025, 7:28 a.m. 🔄 Last Modified: April 22, 2026, 12:30 a.m.

5.3

CVSS3.1

CVE-2025-13405 - Ace Post Type Builder <= 1.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Custo…

The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing authorization validation on the cptb_delete_custom_taxonomy() function in all versions up to, and including, 1.9. This makes it possible for authenticated attackers, with Subscriber-…

📅 Published: Nov. 25, 2025, 7:28 a.m. 🔄 Last Modified: April 21, 2026, 1:30 a.m.

6.5

CVSS3.1

CVE-2025-13380 - AI Engine for WordPress: ChatGPT, GPT Content Generator <= 1.0.1 - Authenticated (Contributor+) Arb…

The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1. This is due to insufficient validation of user-supplied file paths in the 'lqdai_update_post' AJAX endpoint and the use of file_get_cont…

📅 Published: Nov. 25, 2025, 7:28 a.m. 🔄 Last Modified: April 21, 2026, 1:30 a.m.

4.3

CVSS3.1

CVE-2025-13382 - Frontend File Manager Plugin <= 23.4 - Insecure Direct Object Reference to Authenticated (Subscribe…

The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file rename requests in the '/wpfm/v1/file-rename' REST API endpoint. This makes it …

📅 Published: Nov. 25, 2025, 7:28 a.m. 🔄 Last Modified: April 21, 2026, 6 p.m.

5.3

CVSS3.1

CVE-2025-13404 - atec Duplicate Page & Post <= 1.2.20 - Missing Authorization to Authenticated (Contributor+) Arbitr…

The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing authorization validation on the duplicate_post() function in all versions up to, and including, 1.2.20. This makes it possible for authenticated attackers, with Contributor-level access…

📅 Published: Nov. 25, 2025, 7:28 a.m. 🔄 Last Modified: April 22, 2026, 12:30 a.m.

4.4

CVSS3.1

CVE-2025-12025 - YouTube Subscribe <= 3.0.0 - Authenticated (Admin+) Stored Cross-Site Scripting via Title and Chann…

The YouTube Subscribe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…

📅 Published: Nov. 25, 2025, 7:28 a.m. 🔄 Last Modified: April 22, 2026, 12:30 p.m.

5.3

CVSS3.1

CVE-2025-13386 - Social Images Widget <= 2.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings De…

The Social Images Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'options_update' function in all versions up to, and including, 2.1. This makes it possible for unauthenticated attackers to delete the plugin's settings via a …

📅 Published: Nov. 25, 2025, 7:28 a.m. 🔄 Last Modified: April 21, 2026, 6 p.m.

5.3

CVSS3.1

CVE-2025-12525 - Locker Content <= 1.0.0 - Unauthenticated Information Exposure

The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'lockerco_submit_post' AJAX endpoint. This makes it possible for unauthenticated attackers to extract content from posts that has been protected by the plugin.

📅 Published: Nov. 25, 2025, 7:28 a.m. 🔄 Last Modified: April 22, 2026, 12:30 a.m.

5.3

CVSS3.1

CVE-2025-13389 - Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization t…

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `get_order_by_id()` function in all versions up to, and including, 14. This makes it possible for unauthenticated attack…

📅 Published: Nov. 25, 2025, 7:28 a.m. 🔄 Last Modified: April 21, 2026, 6 p.m.
Total resulsts: 349182
Page 2908 of 34,919
« previous page » next page
Filters