5.3
CVE-2025-12814 - SiteSEO β SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings Reset
The SiteSEO β SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect capability check on the siteseo_reset_settings function in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, who have been granted acceβ¦
4.3
CVE-2025-12822 - WP Login and Register using JWT <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) APIβ¦
The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mo_jwt_generate_new_api_key' function in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Subscriber-leveβ¦
5.4
CVE-2025-12359 - Responsive Lightbox & Gallery <= 2.5.3 - Authenticated (Author+) Server-Side Request Forgery
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' function. This is due to insufficient validation of user-supplied URLs when determining image dimensions for gallery items.β¦
6.5
CVE-2025-12174 - Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing Aβ¦
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'directorist_prepare_listings_export_file' and 'directorist_type_slug_change' AJAX actions in all versions up to, andβ¦
6.4
CVE-2025-12878 - FunnelKit β Funnel Builder for WooCommerce Checkout <= 3.13.1.2 - Authenticated (Contributor+) Storβ¦
The FunnelKit β Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wfop_phone` shortcode in all versions up to, and including, 3.13.1.2. This is due to insufficient input sanitization and output escaping on the user-supplied `default` β¦
7.2
CVE-2025-13145 - WP Import β Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP β¦
The WP Import β Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.33.1. This is due to deserialization of untrusted data supplied via CSV file imports in the import_single_post_as_csv function within SingleImpoβ¦
7.5
CVE-2025-12646 - Community Events <= 1.5.4 - Unauthenticated SQL Injection
The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unβ¦
6.4
CVE-2025-13054 - User Profile Builder β Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.β¦
The User Profile Builder β Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escapβ¦
6.4
CVE-2025-12710 - Pet-Manager β Petfinder <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via kwmβ¦
The Pet-Manager β Petfinder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kwm-petfinder shortcode in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated β¦
4.3
CVE-2025-12751 - WSChat β WordPress Live Chat <= 3.1.6 - Missing Authorization to Authenticated (Subscriber+) Settinβ¦
The WSChat β WordPress Live Chat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'reset_settings' AJAX endpoint in all versions up to, and including, 3.1.6. This makes it possible for authenticated attackers, with Subscriber-level accβ¦