6.1

CVSS3.1

CVE-2025-12406 - Project Honey Pot Spam Trap <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Project Honey Pot Spam Trap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the printAdminPage() function. This makes it possible for unauthenticated attackers to update setting…

📅 Published: Nov. 18, 2025, 8:27 a.m. 🔄 Last Modified: April 21, 2026, 1:45 a.m.

4.3

CVSS3.1

CVE-2025-12961 - Download Panel <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Set…

The Download Panel plugin for WordPress is vulnerable to unauthorized settings modification due to a missing capability check on the 'wp_ajax_save_settings' AJAX action in all versions up to, and including, 1.3.3. This is due to the absence of any capability verification in the `dlpn_save_settings(…

📅 Published: Nov. 18, 2025, 8:27 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

8.8

CVSS3.1

CVE-2025-13088 - Category and Product Woocommerce Tabs <= 1.0 - Authenticated (Contributor+) Local File Inclusion

The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0. This is due to insufficient input validation on the 'template' parameter in the categoryProductTab() function. This makes it possible for authenticated att…

📅 Published: Nov. 18, 2025, 8:27 a.m. 🔄 Last Modified: April 21, 2026, 1:45 a.m.

4.3

CVSS3.1

CVE-2025-12372 - The Permalinks Cascade <= 2.2 - Missing Authorization To Authenticated (Subscriber+) Plugin Setting…

The Permalinks Cascade plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action in the handleTPCAdminAjaxRequest function. This makes it possible for authent…

📅 Published: Nov. 18, 2025, 8:27 a.m. 🔄 Last Modified: April 21, 2026, 1:45 a.m.

8.8

CVSS3.1

CVE-2025-12775 - WP Dropzone <= 1.1.0 - Authenticated (Subscriber+) Arbitrary File Upload

The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 1.1.0 via the `ajax_upload_handle` function. This is due to the chunked upload functionality writing files directly to the uploads directory before any file type validatio…

📅 Published: Nov. 18, 2025, 8:27 a.m. 🔄 Last Modified: April 21, 2026, 1:45 a.m.

6.4

CVSS3.1

CVE-2025-8609 - RTMKit Addons <= 1.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Rep…

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion Block's attributes in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible …

📅 Published: Nov. 18, 2025, 8:27 a.m. 🔄 Last Modified: April 20, 2026, 9:45 p.m.

4.3

CVSS3.1

CVE-2025-12173 - WP Admin Microblog <= 3.1.1 - Cross-Site Request Forgery to Message Creation

The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the 'wp-admin-microblog' page. This makes it possible for unauthenticated attackers to send messages on behalf…

📅 Published: Nov. 18, 2025, 8:27 a.m. 🔄 Last Modified: April 22, 2026, noon

6.5

CVSS3.1

CVE-2025-12937 - ACF Flexible Layouts Manager <= 1.1.6 - Missing Authorization to Unauthenticated Custom Field Update

The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'acf_flm_update_template_with_pasted_layout' function in all versions up to, and including, 1.1.6. This makes it possible for unauthenticated attackers t…

📅 Published: Nov. 18, 2025, 8:27 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2025-8605 - Gutenify - Visual Site Builder Blocks & Site Templates <= 1.5.9 - Authenticated (Contributor+) Stor…

The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This ma…

📅 Published: Nov. 18, 2025, 8:27 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

4.3

CVSS3.1

CVE-2025-12827 - Top Friends <= 0.3 - Cross-Site Request Forgery to Settings Update

The Top Friends plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing nonce validation on the top_friends_options_subpanel() function. This makes it possible for unauthenticated attackers to modify plugin settings via a fo…

📅 Published: Nov. 18, 2025, 8:27 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.
Total resulsts: 349182
Page 2980 of 34,919
« previous page » next page
Filters