6.4

CVSS3.1

CVE-2025-12711 - Share to Google Classroom <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via sha…

The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:30 p.m.

9.8

CVSS3.1

CVE-2025-12813 - Holiday class post calendar <= 7.1 - Unauthenticated Remote Code Execution via 'contents'

The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'contents' parameter. This is due to a lack of sanitization of user-supplied data when creating a cache file. This makes it possible for unauthenticated atta…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:30 p.m.

9.8

CVSS3.1

CVE-2025-11457 - EasyCommerce – AI-Powered, Blazing-Fast & Beautiful WordPress Ecommerce Plugin 0.9.0-beta2 - 1.8.2 …

The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in versions 0.9.0-beta2 to 1.8.2. This is due to the /easycommerce/v1/orders REST API endpoint not properly restricting the ability for users to select roles during …

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 12:30 p.m.

6.4

CVSS3.1

CVE-2025-11856 - Eventbee Ticketing Widget <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketwidget' shortcode in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input and output of several parameters. This makes it possible f…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 12:30 p.m.

6.1

CVSS3.1

CVE-2025-12590 - YSlider <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 1.1. This is due to missing nonce verification on the content configuration page and insufficient input sanitization and output escaping. This makes it p…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:30 p.m.

6.1

CVSS3.1

CVE-2025-12021 - WP-OAuth <= 0.4.1 - Reflected Cross-Site Scripting

The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, noon

4.3

CVSS3.1

CVE-2025-12588 - USB Qr Code Scanner For Woocommerce <= 1.0.0 - Cross-Site Request Forgery to Settings Update

The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the settings page. This makes it possible for unauthenticated attackers to update the plugin's settings vi…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:30 p.m.

4.9

CVSS3.1

CVE-2025-12020 - Double the Donation <= 3.0.0 - Authenticated (Admin+) Stored Cross-Site Scripting

The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for …

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 12:30 p.m.

4.3

CVSS3.1

CVE-2025-12132 - WP Custom Admin Login Page Logo <= 1.4.8.4 - Cross-Site Request Forgery to Settings Update

The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.8.4. This is due to missing or incorrect nonce validation on the wpclpl_save functionality. This makes it possible for unauthenticated attackers to modify t…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, noon

6.1

CVSS3.1

CVE-2025-12589 - WP-Walla <= 0.5.3.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 0.5.3.5. This is due to missing nonce verification on the settings page and insufficient input sanitization and output escaping. This makes it possible …

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:30 p.m.
Total resulsts: 348415
Page 3003 of 34,842
Β« previous page Β» next page
Filters