6.5

CVSS3.1

CVE-2025-12010 - Authors List <= 2.0.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Limited M…

The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_List_Shortcode class. This makes it possible for authenticated attackers, with Contributor-level access and above, to ca…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 1 p.m.

6.4

CVSS3.1

CVE-2025-12754 - Geopost <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost' shortcode in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:45 p.m.

6.4

CVSS3.1

CVE-2025-11805 - Skip to Timestamp <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in all versions up to, and including, 1.4.4. This is due to insufficient input sanitization and output escaping on the 'time' attribute. This makes it possible for authenticated attack…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 2 p.m.

6.4

CVSS3.1

CVE-2025-12644 - Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress <= 1.0.11 - Authe…

The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nonaki' shortcode in all versions up to, and including, 1.0.11. This is due to insufficient input sanitization and output escaping on user supplied custom fiel…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:45 p.m.

4.3

CVSS3.1

CVE-2025-11886 - CTL Arcade Lite <= 1.0 - Cross-Site Request Forgery to Plugin Activation and Deactivation

The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'ctl_arcade_lite_page_manage_games' page. This makes it possible for unauthenticated attackers to deactivate an…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 12:30 p.m.

5.5

CVSS3.1

CVE-2025-12632 - RandomQuotr <= 1.0.4 - Authenticated (Admin+) Stored Cross-Site Scripting

The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:45 p.m.

4.4

CVSS3.1

CVE-2025-12538 - Fleet Manager <= 2.5.1 - Authenticated (Editor+) Stored Cross-Site Scripting

The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above,…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:45 p.m.

5.4

CVSS3.1

CVE-2025-12880 - Progress Bar Blocks for Gutenberg <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting vi…

The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level …

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 21, 2026, 6:45 p.m.

5.3

CVSS3.1

CVE-2025-11996 - Find Unused Images <= 1.0.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion

The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() functiosn in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to delete all of…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 12:15 p.m.

6.4

CVSS3.1

CVE-2025-11863 - My Geo Posts Free <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode in all versions up to, and including, 1.2. This is due to the plugin not properly sanitizing user input or escaping output of the 'default' shortcode attribute. This makes it possi…

πŸ“… Published: Nov. 11, 2025, 3:30 a.m. πŸ”„ Last Modified: April 22, 2026, 1 p.m.
Total resulsts: 349182
Page 3081 of 34,919
Β« previous page Β» next page
Filters