5.3

CVSS3.1

CVE-2025-12877 - IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to …

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability check on the panding_blood_request_action() function in all versions up to, and including, 2.1.15. This makes it possible for unauthe…

πŸ“… Published: Nov. 22, 2025, 7:29 a.m. πŸ”„ Last Modified: April 21, 2026, 6:15 p.m.

5.3

CVSS3.1

CVE-2025-12752 - Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creation

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fak…

πŸ“… Published: Nov. 22, 2025, 7:29 a.m. πŸ”„ Last Modified: April 22, 2026, 12:30 a.m.

7.5

CVSS3.1

CVE-2025-13384 - CP Contact Form with PayPal <= 1.3.56 - Missing Authorization to Unauthenticated Arbitrary Payment …

The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.56. This is due to the plugin exposing an unauthenticated IPN-like endpoint (via the 'cp_contactformpp_ipncheck' query parameter) that processes payment confirmation…

πŸ“… Published: Nov. 22, 2025, 7:29 a.m. πŸ”„ Last Modified: April 21, 2026, 6:15 p.m.

5.3

CVSS3.1

CVE-2025-13317 - Appointment Booking Calendar <= 1.3.96 - Missing Authorization to Arbitrary Booking Confirmation vi…

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the plugin exposing an unauthenticated booking processing endpoint (cpabc_appointments_check_IPN_verification) that trusts attacker-supplied paym…

πŸ“… Published: Nov. 22, 2025, 7:29 a.m. πŸ”„ Last Modified: April 22, 2026, 12:30 a.m.

0.0

CVE-2025-13541 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Nov. 22, 2025, 7:22 a.m. πŸ”„ Last Modified: Nov. 24, 2025, 2:34 p.m.

6.4

CVSS3.1

CVE-2025-11186 - Cookie Notice & Compliance for GDPR / CCPA <= 2.5.8 - Authenticated (Contributor+) Stored Cross-Sit…

The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookies_accepted shortcode in all versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

πŸ“… Published: Nov. 22, 2025, 5:07 a.m. πŸ”„ Last Modified: April 22, 2026, 9:15 p.m.

2.3

CVSS4.0

CVE-2025-12889 - TLS 1.2 Client Can Downgrade Digest Used

With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest.

πŸ“… Published: Nov. 21, 2025, 11:06 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 3:39 p.m.

2.3

CVSS4.0

CVE-2025-11932 - Timing Side-Channel in PSK Binder Verification

The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder

πŸ“… Published: Nov. 21, 2025, 11:01 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 3:39 p.m.

2.1

CVSS4.0

CVE-2025-11931 - Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt

Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha20Poly1305_Decrypt() which is not used with TLS connections, only from direct calls from an application.

πŸ“… Published: Nov. 21, 2025, 10:57 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 3:38 p.m.

1

CVSS4.0

CVE-2025-12888 - Constant Time Issue with Xtensa-based ESP32 and X22519

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X2551…

πŸ“… Published: Nov. 21, 2025, 10:50 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 3:51 p.m.
Total resulsts: 349182
Page 2929 of 34,919
Β« previous page Β» next page
Filters