6.4

CVSS3.1

CVE-2025-11860 - Twitter Feed <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in all versions up to, and including, 1.3.1. This is due to the plugin not properly sanitizing user input and output of the 'width' and 'height' parameters. This makes it possible f…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 1:45 a.m.

6.4

CVSS3.1

CVE-2025-11821 - Woocommerce – Products By Custom Tax <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Script…

The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_products_custom_tax' shortcode in all versions up to, and including, 2.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This make…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 12:45 a.m.

6.4

CVSS3.1

CVE-2025-12668 - WP Count Down Timer <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 1:45 a.m.

6.4

CVSS3.1

CVE-2025-12658 - Preload Current Images <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortc…

The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' parameter in the 'preload_progress_bar' shortcode in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping on user supplied attributes…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2025-11859 - Paypal Donation Shortcode <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in all versions up to, and including, 0.1. This is due to the plugin not properly sanitizing user input and output of the 'title' and 'text' parameters. This makes it possible …

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 1:45 a.m.

5.3

CVSS3.1

CVE-2025-11532 - Wisly <= 1.0.0 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation

The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.0 due to missing validation on the 'wishlist_id' user controlled key. This makes it possible for unauthenticated attackers to remove and add items to other user's wishlists.

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 12:45 a.m.

4.4

CVSS3.1

CVE-2025-12631 - Squirrels Auto Inventory <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting

The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level perm…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

4.3

CVSS3.1

CVE-2025-12665 - Ninja Countdown <= 1.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Countdown…

The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ninja_countdown_admin_ajax' AJAX endpoint in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with S…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2025-12671 - WP-Iconics <= 0.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_iconics' shortcode in all versions up to, and including, 0.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Con…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2025-11869 - Precise Columns <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attribute in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input or escaping output when inserting the wrapper ID into the generated HTM…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 12:30 p.m.
Total resulsts: 348389
Page 2999 of 34,839
« previous page » next page
Filters