10

CVSS3.1

CVE-2025-64090 - Authenticated Remote Code Execution in device hostname

This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

πŸ“… Published: Jan. 9, 2026, 9:59 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 6:15 p.m.

6.1

CVSS3.1

CVE-2025-13895 - Top Position Google Finance <= 0.1.0 - Reflected Cross-Site Scripting

The Top Position Google Finance plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 0.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t…

πŸ“… Published: Jan. 9, 2026, 9:19 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 6:01 p.m.

6.4

CVSS3.1

CVE-2025-13900 - WP Popup Magic <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Short…

The WP Popup Magic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the [wppum_end] shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

πŸ“… Published: Jan. 9, 2026, 9:19 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 6:02 p.m.

6.4

CVSS3.1

CVE-2025-13853 - Nearby Now Reviews <= 5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode …

The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter of the nn-tech shortcode in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w…

πŸ“… Published: Jan. 9, 2026, 9:19 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 9:19 a.m.

6.4

CVSS3.1

CVE-2025-13729 - Entry Views <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Entry Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'entry-views' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

πŸ“… Published: Jan. 9, 2026, 9:19 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 6:02 p.m.

6.4

CVSS3.1

CVE-2026-0627 - AMP for WP <= 1.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG File Upload

The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.1.10. This is due to insufficient sanitization of SVG file content that only removes `<script>` tags while allowing other XSS vectors such as event handlers …

πŸ“… Published: Jan. 9, 2026, 8:20 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 8:20 a.m.

7.2

CVSS3.1

CVE-2025-14657 - Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4…

The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including, 4.0.51. This makes it possible for unauthenti…

πŸ“… Published: Jan. 9, 2026, 7:22 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 6:07 p.m.

4.3

CVSS3.1

CVE-2025-13753 - WP Table Builder <= 2.0.19 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Table…

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect authorization check on the save_table() function in all versions up to, and including, 2.0.19. This makes it possible for authenticated attackers, with Subscr…

πŸ“… Published: Jan. 9, 2026, 7:22 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 6:09 p.m.

4.3

CVSS3.1

CVE-2025-13935 - Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated …

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completion in all versions up to, and including, 3.9.2. This is due to missing enrollment verification in the 'mark_course_complete' function. This makes it possible for authenticated atta…

πŸ“… Published: Jan. 9, 2026, 7:22 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 6:10 p.m.

4.3

CVSS3.1

CVE-2025-13934 - Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated …

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollment in all versions up to, and including, 3.9.3. This is due to a missing capability check and purchasability validation in the `course_enrollment()` AJAX handler. This makes it pos…

πŸ“… Published: Jan. 9, 2026, 7:22 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 7:11 p.m.
Total resulsts: 327160
Page 31 of 32,716
Β« previous page Β» next page
Filters