4.3

CVSS3.1

CVE-2025-11983 - WP Discourse <= 2.5.9 - Authenticated (Author+) Information Exposure

The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9. This is due to the plugin unconditionally sending Discourse API credentials (Api-Key and Api-Username headers) to any host specified in a post's discourse_permalink custom field …

📅 Published: Nov. 1, 2025, 5:40 a.m. 🔄 Last Modified: April 22, 2026, 12:15 p.m.

6.4

CVSS3.1

CVE-2025-12090 - Employee Spotlight – Team Member Showcase & Meet the Team Plugin <= 5.1.2 - Authenticated (Contribu…

The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social URLs in all versions up to, and including, 5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att…

📅 Published: Nov. 1, 2025, 5:40 a.m. 🔄 Last Modified: April 22, 2026, 12:15 p.m.

4.3

CVSS3.1

CVE-2025-12180 - Qi Blocks <= 1.4.3 - Missing Authorization to Authenticated (Contributor+) Plugin Settings Update

The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin storing arbitrary CSS styles submitted via the `qi-blocks/v1/update-styles` REST API endpoint without proper sanitization in the `update_global_styles_cal…

📅 Published: Nov. 1, 2025, 5:40 a.m. 🔄 Last Modified: April 22, 2026, 12:45 p.m.

4.4

CVSS3.1

CVE-2025-11927 - Flying Images: Optimize and Lazy Load Images for Faster Page Speed <= 2.4.14 - Authenticated (Admin…

The Flying Images: Optimize and Lazy Load Images for Faster Page Speed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticat…

📅 Published: Nov. 1, 2025, 4:27 a.m. 🔄 Last Modified: April 21, 2026, 6:45 p.m.

8.8

CVSS3.1

CVE-2025-5949 - Service Finder Bookings <= 6.0 - Authenticated (Subscriber+) Privilege Escalation via change_candid…

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to processing a password change request. This makes it possible for authen…

📅 Published: Nov. 1, 2025, 4:27 a.m. 🔄 Last Modified: April 20, 2026, 9:45 p.m.

6.4

CVSS3.1

CVE-2025-12118 - Schema Scalpel <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title i…

The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping when outputting user-supplied data into JSON-LD schema markup. This makes it possible for au…

📅 Published: Nov. 1, 2025, 4:27 a.m. 🔄 Last Modified: April 22, 2026, 1 p.m.

7.2

CVSS3.1

CVE-2025-11995 - Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting

The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr…

📅 Published: Nov. 1, 2025, 4:27 a.m. 🔄 Last Modified: April 22, 2026, 12:15 p.m.

4.3

CVSS3.1

CVE-2025-11377 - List category posts <= 0.92.0 - Authenticated (Contributor+) Information Exposure

The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.92.0 via the 'catlist' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with contributor-level acc…

📅 Published: Nov. 1, 2025, 4:27 a.m. 🔄 Last Modified: April 22, 2026, 12:45 p.m.

4.4

CVSS3.1

CVE-2025-11928 - CSS & JavaScript Toolbox <= 12.0.5 - Authenticated (Admin+) Stored Cross-Site Scripting

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 12.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level per…

📅 Published: Nov. 1, 2025, 3:34 a.m. 🔄 Last Modified: April 21, 2026, 2 a.m.

4.3

CVSS3.1

CVE-2025-12367 - SiteSEO – SEO Simplified <= 1.3.1 - Missing Authorization to Authenticated (Author+) Plugin Setting…

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.3.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Author-level ac…

📅 Published: Nov. 1, 2025, 3:34 a.m. 🔄 Last Modified: April 22, 2026, noon
Total resulsts: 346554
Page 2923 of 34,656
« previous page » next page
Filters