5.3

CVSS3.1

CVE-2025-12814 - SiteSEO – SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings Reset

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect capability check on the siteseo_reset_settings function in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, who have been granted acce…

πŸ“… Published: Nov. 19, 2025, 5:45 a.m. πŸ”„ Last Modified: April 21, 2026, 1:30 a.m.

4.3

CVSS3.1

CVE-2025-12822 - WP Login and Register using JWT <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) API…

The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mo_jwt_generate_new_api_key' function in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Subscriber-leve…

πŸ“… Published: Nov. 19, 2025, 5:45 a.m. πŸ”„ Last Modified: April 21, 2026, 6:15 p.m.

5.4

CVSS3.1

CVE-2025-12359 - Responsive Lightbox & Gallery <= 2.5.3 - Authenticated (Author+) Server-Side Request Forgery

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' function. This is due to insufficient validation of user-supplied URLs when determining image dimensions for gallery items.…

πŸ“… Published: Nov. 19, 2025, 5:45 a.m. πŸ”„ Last Modified: April 22, 2026, noon

6.5

CVSS3.1

CVE-2025-12174 - Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing A…

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'directorist_prepare_listings_export_file' and 'directorist_type_slug_change' AJAX actions in all versions up to, and…

πŸ“… Published: Nov. 19, 2025, 5:45 a.m. πŸ”„ Last Modified: April 22, 2026, 1 p.m.

6.4

CVSS3.1

CVE-2025-12878 - FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.13.1.2 - Authenticated (Contributor+) Stor…

The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wfop_phone` shortcode in all versions up to, and including, 3.13.1.2. This is due to insufficient input sanitization and output escaping on the user-supplied `default` …

πŸ“… Published: Nov. 19, 2025, 5:45 a.m. πŸ”„ Last Modified: April 21, 2026, 6:15 p.m.

7.2

CVSS3.1

CVE-2025-13145 - WP Import – Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP …

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.33.1. This is due to deserialization of untrusted data supplied via CSV file imports in the import_single_post_as_csv function within SingleImpo…

πŸ“… Published: Nov. 19, 2025, 5:45 a.m. πŸ”„ Last Modified: April 21, 2026, 6:15 p.m.

7.5

CVSS3.1

CVE-2025-12646 - Community Events <= 1.5.4 - Unauthenticated SQL Injection

The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for un…

πŸ“… Published: Nov. 19, 2025, 5:45 a.m. πŸ”„ Last Modified: April 22, 2026, 12:45 a.m.

6.4

CVSS3.1

CVE-2025-13054 - User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.…

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escap…

πŸ“… Published: Nov. 19, 2025, 5:45 a.m. πŸ”„ Last Modified: April 21, 2026, 6:15 p.m.

6.4

CVSS3.1

CVE-2025-12710 - Pet-Manager – Petfinder <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via kwm…

The Pet-Manager – Petfinder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kwm-petfinder shortcode in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated …

πŸ“… Published: Nov. 19, 2025, 5:45 a.m. πŸ”„ Last Modified: April 21, 2026, 6:15 p.m.

4.3

CVSS3.1

CVE-2025-12751 - WSChat – WordPress Live Chat <= 3.1.6 - Missing Authorization to Authenticated (Subscriber+) Settin…

The WSChat – WordPress Live Chat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'reset_settings' AJAX endpoint in all versions up to, and including, 3.1.6. This makes it possible for authenticated attackers, with Subscriber-level acc…

πŸ“… Published: Nov. 19, 2025, 5:45 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2964 of 34,919
Β« previous page Β» next page
Filters