6.4

CVSS3.1

CVE-2025-11859 - Paypal Donation Shortcode <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in all versions up to, and including, 0.1. This is due to the plugin not properly sanitizing user input and output of the 'title' and 'text' parameters. This makes it possible …

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 1:45 a.m.

5.3

CVSS3.1

CVE-2025-11532 - Wisly <= 1.0.0 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation

The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.0 due to missing validation on the 'wishlist_id' user controlled key. This makes it possible for unauthenticated attackers to remove and add items to other user's wishlists.

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 12:45 a.m.

4.4

CVSS3.1

CVE-2025-12631 - Squirrels Auto Inventory <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting

The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level perm…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

4.3

CVSS3.1

CVE-2025-12665 - Ninja Countdown <= 1.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Countdown…

The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ninja_countdown_admin_ajax' AJAX endpoint in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with S…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2025-12671 - WP-Iconics <= 0.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_iconics' shortcode in all versions up to, and including, 0.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Con…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2025-11869 - Precise Columns <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attribute in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input or escaping output when inserting the wrapper ID into the generated HTM…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 12:30 p.m.

4.3

CVSS3.1

CVE-2025-12526 - Private Google Calendars <= 20250811 - Missing Authorization to Authenticated (Subscriber+) Setting…

The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pgc_remove' action in all versions up to, and including, 20250811. This makes it possible for authenticated attackers, with Subscriber-level access and abov…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, noon

6.4

CVSS3.1

CVE-2025-11828 - Magazine Companion <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribute in the bnm-blocks/featured-posts-1 block in all versions up to, and including, 1.2.3. This is due to insufficient input sanitization and output escaping when using user-supplie…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 1 p.m.

6.4

CVSS3.1

CVE-2025-12753 - Chart Expert <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes. This makes it possible for authenti…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

9.8

CVSS3.1

CVE-2025-11170 - WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload

The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Cpiwm_Import_Controller::import function in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 1 p.m.
Total resulsts: 348395
Page 3000 of 34,840
« previous page » next page
Filters