3.4

CVSS3.1

CVE-2025-66062 - WordPress WP YouTube Lyte plugin <= 1.7.28 - Open Redirection vulnerability

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allows Phishing.This issue affects WP YouTube Lyte: from n/a through <= 1.7.28.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:35 p.m.

4.3

CVSS3.1

CVE-2025-66061 - WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Cross Site Request Forgery (CSRF) vulnerab…

Cross-Site Request Forgery (CSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Cross Site Request Forgery.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:35 p.m.

5.3

CVSS3.1

CVE-2025-66060 - WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:35 p.m.

5.3

CVSS3.1

CVE-2025-66059 - WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Retrieve Embedded Sensitive Data.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:35 p.m.

6.5

CVSS3.1

CVE-2025-66057 - WordPress Bold Page Builder plugin <= 5.5.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows DOM-Based XSS.This issue affects Bold Page Builder: from n/a through <= 5.5.2.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:35 p.m.

4.3

CVSS3.1

CVE-2025-66056 - WordPress Uncanny Automator plugin < 6.10.0 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Retrieve Embedded Sensitive Data.This issue affects Uncanny Automator: from n/a through < 6.10.0.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-66055 - WordPress Email Subscribers & Newsletters plugin <= 5.9.10 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-66053 - WordPress Enfold theme <= 7.1.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold enfold allows Stored XSS.This issue affects Enfold: from n/a through <= 7.1.2.

πŸ“… Published: Nov. 21, 2025, 12:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-10039 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.2.9 - Authenticated (Subscriber+) Insecure…

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.9 via the 'eh_crm_ticket_single_view_client' due to missing validation on a user controlled key. This makes it possible for authen…

πŸ“… Published: Nov. 21, 2025, 12:28 p.m. πŸ”„ Last Modified: April 21, 2026, 1:30 a.m.

6.4

CVSS3.1

CVE-2025-12935 - FluentCRM - Marketing Automation For WordPress <= 2.9.84 - Authenticated (Contributor+) Stored Cros…

The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fluentcrm_content' shortcode in all versions up to, and including, 2.9.84 due to insufficient input san…

πŸ“… Published: Nov. 21, 2025, 12:28 p.m. πŸ”„ Last Modified: April 22, 2026, 6:15 a.m.
Total resulsts: 349182
Page 2938 of 34,919
Β« previous page Β» next page
Filters