4.3

CVSS3.1

CVE-2025-12588 - USB Qr Code Scanner For Woocommerce <= 1.0.0 - Cross-Site Request Forgery to Settings Update

The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the settings page. This makes it possible for unauthenticated attackers to update the plugin's settings vi…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:30 p.m.

4.9

CVSS3.1

CVE-2025-12020 - Double the Donation <= 3.0.0 - Authenticated (Admin+) Stored Cross-Site Scripting

The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for …

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 12:30 p.m.

4.3

CVSS3.1

CVE-2025-12132 - WP Custom Admin Login Page Logo <= 1.4.8.4 - Cross-Site Request Forgery to Settings Update

The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.8.4. This is due to missing or incorrect nonce validation on the wpclpl_save functionality. This makes it possible for unauthenticated attackers to modify t…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, noon

6.1

CVSS3.1

CVE-2025-12589 - WP-Walla <= 0.5.3.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 0.5.3.5. This is due to missing nonce verification on the settings page and insufficient input sanitization and output escaping. This makes it possible …

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2025-12672 - Flickr Show <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'div_height' parameter of the 'flickrshow' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:45 p.m.

5.3

CVSS3.1

CVE-2025-11997 - Document Pro Elementor – Documentation & Knowledge Base <= 1.0.9 - Unauthenticated Information Expo…

The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.9. This is due to the plugin exposing sensitive Algolia API keys through the frontend JavaScript code via wp_localize_script without prope…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 12:30 p.m.

7.5

CVSS3.1

CVE-2025-11451 - Auto Amazon Links – Amazon Associates Affiliate Plugin <= 5.4.3 - Unauthenticated Arbitrary File Re…

The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4.3 via the '/wp-json/wp/v2/aal_ajax_unit_loading' RST API endpoint. This makes it possible for unauthenticated attackers to read the conten…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 12:30 p.m.

6.5

CVSS3.1

CVE-2025-12010 - Authors List <= 2.0.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Limited M…

The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_List_Shortcode class. This makes it possible for authenticated attackers, with Contributor-level access and above, to ca…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 1 p.m.

6.4

CVSS3.1

CVE-2025-12754 - Geopost <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost' shortcode in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:45 p.m.

6.4

CVSS3.1

CVE-2025-11805 - Skip to Timestamp <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in all versions up to, and including, 1.4.4. This is due to insufficient input sanitization and output escaping on the 'time' attribute. This makes it possible for authenticated attack…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 2 p.m.
Total resulsts: 348419
Page 3004 of 34,842
Β« previous page Β» next page
Filters