4.3

CVSS3.1

CVE-2025-12015 - Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pag…

The Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_wpqai_disconnect_quicq_afosto' AJAX endpoint in all versions up to,…

πŸ“… Published: Nov. 13, 2025, 8:27 a.m. πŸ”„ Last Modified: April 22, 2026, 9:15 p.m.

7.1

CVSS3.1

CVE-2025-12844 - AI Engine <= 3.1.8 - Authenticated (Subscriber+) PHP Object Injection via PHAR Deserialization

The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via deserialization of untrusted input in the 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' functions. This makes it possible for authenticated a…

πŸ“… Published: Nov. 13, 2025, 7:27 a.m. πŸ”„ Last Modified: April 21, 2026, 1:45 a.m.

5.3

CVSS3.1

CVE-2025-12681 - Comment Edit Core – Simple Comment Editing <= 3.1.0 - Unauthenticated Sensitive Information Exposure

The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.0 via the 'ajax_get_comment' function. This makes it possible for unauthenticated attackers to extract sensitive data including user IDs, IP …

πŸ“… Published: Nov. 13, 2025, 7:27 a.m. πŸ”„ Last Modified: April 22, 2026, 12:45 a.m.

4.9

CVSS3.1

CVE-2025-12620 - Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 6.0.7 - Authenticated (Administrator+) S…

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the β€˜filterbyauthor’ parameter in all versions up to, and including, 6.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on th…

πŸ“… Published: Nov. 13, 2025, 5:30 a.m. πŸ”„ Last Modified: April 22, 2026, 12:45 a.m.

5.3

CVSS3.1

CVE-2025-12891 - Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Information Exposure

The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results' AJAX endpoint in all versions up to, and including, 5.1.9.4. This makes it possible for unauthenticated attackers to view all survey submissions.

πŸ“… Published: Nov. 13, 2025, 4:28 a.m. πŸ”„ Last Modified: April 21, 2026, 6:30 p.m.

8.8

CVSS3.1

CVE-2025-11923 - LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes - Various Versions - Authenticated (Stu…

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalation. This is due to the plugin not properly validating a user's identity prior to allowing them to modify their own role via the REST API. The permission check in the update_item_p…

πŸ“… Published: Nov. 13, 2025, 3:27 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-12536 - SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure

The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to …

πŸ“… Published: Nov. 13, 2025, 3:27 a.m. πŸ”„ Last Modified: April 21, 2026, 6:30 p.m.

8.8

CVSS3.1

CVE-2025-12733 - Import any XML, CSV or Excel File to WordPress (WP All Import) <= 3.9.6 - Authenticated (Administra…

The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.9.6. This is due to the use of eval() on unsanitized user-supplied input in the pmxi_if function within helpers/functions.php. This …

πŸ“… Published: Nov. 13, 2025, 3:27 a.m. πŸ”„ Last Modified: April 21, 2026, 6:30 p.m.

5.3

CVSS3.1

CVE-2025-12892 - Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Limited Option Update

The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 5.1.9.4. This makes it possible for unauthenticated attackers to update the ays_survey_maker_up…

πŸ“… Published: Nov. 13, 2025, 3:27 a.m. πŸ”„ Last Modified: April 22, 2026, 12:45 a.m.

5.3

CVSS3.1

CVE-2025-12979 - Welcart e-Commerce <= 2.11.24 - Missing Authorization to Unauthenticated Information Exposure

The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' action in all versions up to, and including, 2.11.24. This makes it possible for unauthenticated attackers to access configured payment credentials (ex. P…

πŸ“… Published: Nov. 13, 2025, 3:27 a.m. πŸ”„ Last Modified: April 22, 2026, 4:45 p.m.
Total resulsts: 349182
Page 3026 of 34,919
Β« previous page Β» next page
Filters