6.4

CVSS3.1

CVE-2025-12671 - WP-Iconics <= 0.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_iconics' shortcode in all versions up to, and including, 0.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Con…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2025-11869 - Precise Columns <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attribute in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input or escaping output when inserting the wrapper ID into the generated HTM…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 12:30 p.m.

4.3

CVSS3.1

CVE-2025-12526 - Private Google Calendars <= 20250811 - Missing Authorization to Authenticated (Subscriber+) Setting…

The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pgc_remove' action in all versions up to, and including, 20250811. This makes it possible for authenticated attackers, with Subscriber-level access and abov…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, noon

6.4

CVSS3.1

CVE-2025-11828 - Magazine Companion <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribute in the bnm-blocks/featured-posts-1 block in all versions up to, and including, 1.2.3. This is due to insufficient input sanitization and output escaping when using user-supplie…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 1 p.m.

6.4

CVSS3.1

CVE-2025-12753 - Chart Expert <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes. This makes it possible for authenti…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

9.8

CVSS3.1

CVE-2025-11170 - WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload

The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Cpiwm_Import_Controller::import function in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 1 p.m.

6.4

CVSS3.1

CVE-2025-12711 - Share to Google Classroom <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via sha…

The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

9.8

CVSS3.1

CVE-2025-12813 - Holiday class post calendar <= 7.1 - Unauthenticated Remote Code Execution via 'contents'

The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'contents' parameter. This is due to a lack of sanitization of user-supplied data when creating a cache file. This makes it possible for unauthenticated atta…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 21, 2026, 6:30 p.m.

9.8

CVSS3.1

CVE-2025-11457 - EasyCommerce – AI-Powered, Blazing-Fast & Beautiful WordPress Ecommerce Plugin 0.9.0-beta2 - 1.8.2 …

The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in versions 0.9.0-beta2 to 1.8.2. This is due to the /easycommerce/v1/orders REST API endpoint not properly restricting the ability for users to select roles during …

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 12:30 p.m.

6.4

CVSS3.1

CVE-2025-11856 - Eventbee Ticketing Widget <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketwidget' shortcode in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input and output of several parameters. This makes it possible f…

📅 Published: Nov. 11, 2025, 3:30 a.m. 🔄 Last Modified: April 22, 2026, 12:30 p.m.
Total resulsts: 348401
Page 3001 of 34,841
« previous page » next page
Filters