8.8

CVSS3.1

CVE-2025-12637 - Elastic Theme Editor <= 0.0.3 - Authenticated (Subscriber+) Arbitrary File Upload

The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation feature in the process_theme function in all versions up to, and including, 0.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upโ€ฆ

๐Ÿ“… Published: Nov. 11, 2025, 3:30 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:45 a.m.

6.4

CVSS3.1

CVE-2025-11882 - Simple Donate <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortcode in versions less than, or equal to, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackโ€ฆ

๐Ÿ“… Published: Nov. 11, 2025, 3:30 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:45 a.m.

6.4

CVSS3.1

CVE-2025-12663 - Jeba Cute forkit <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Jeba Cute forkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter in the 'jeba_forkit' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it posโ€ฆ

๐Ÿ“… Published: Nov. 11, 2025, 3:30 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:45 a.m.

6.4

CVSS3.1

CVE-2025-11860 - Twitter Feed <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in all versions up to, and including, 1.3.1. This is due to the plugin not properly sanitizing user input and output of the 'width' and 'height' parameters. This makes it possible fโ€ฆ

๐Ÿ“… Published: Nov. 11, 2025, 3:30 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:45 a.m.

6.4

CVSS3.1

CVE-2025-11821 - Woocommerce โ€“ Products By Custom Tax <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scriptโ€ฆ

The Woocommerce โ€“ Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_products_custom_tax' shortcode in all versions up to, and including, 2.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makeโ€ฆ

๐Ÿ“… Published: Nov. 11, 2025, 3:30 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 12:45 a.m.

6.4

CVSS3.1

CVE-2025-12668 - WP Count Down Timer <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atโ€ฆ

๐Ÿ“… Published: Nov. 11, 2025, 3:30 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:45 a.m.

6.4

CVSS3.1

CVE-2025-12658 - Preload Current Images <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcโ€ฆ

The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' parameter in the 'preload_progress_bar' shortcode in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping on user supplied attributesโ€ฆ

๐Ÿ“… Published: Nov. 11, 2025, 3:30 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2025-11859 - Paypal Donation Shortcode <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in all versions up to, and including, 0.1. This is due to the plugin not properly sanitizing user input and output of the 'title' and 'text' parameters. This makes it possible โ€ฆ

๐Ÿ“… Published: Nov. 11, 2025, 3:30 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:45 a.m.

5.3

CVSS3.1

CVE-2025-11532 - Wisly <= 1.0.0 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation

The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.0 due to missing validation on the 'wishlist_id' user controlled key. This makes it possible for unauthenticated attackers to remove and add items to other user's wishlists.

๐Ÿ“… Published: Nov. 11, 2025, 3:30 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 12:45 a.m.

4.4

CVSS3.1

CVE-2025-12631 - Squirrels Auto Inventory <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting

The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permโ€ฆ

๐Ÿ“… Published: Nov. 11, 2025, 3:30 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 6:30 p.m.
Total resulsts: 349182
Page 3078 of 34,919
ยซ previous page ยป next page
Filters