4.3

CVSS3.1

CVE-2025-12156 - Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One 2.0.7 - 2.2.6 - Missing…

The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_post_data() function in versions 2.0.7 to 2.2.6. This makes it possible for authenticated attackers, …

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-11724 - EM Beer Manager <= 3.2.3 - Authenticated (Subscriber+) Arbitrary File Upload

The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all versions up to, and including, 3.2.3. This is due to missing file type validation in the EMBM_Admin_Untappd_Import_image() function and missing authorization checks on the wp_ajax…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 22, 2026, 12:45 p.m.

6.1

CVSS3.1

CVE-2025-12456 - Centangle Team Showcase <= 1.0.0 - Cross-Site Request Forgery To Plugin's Settings Modification And…

The Centangle-Team plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to modify plugin's settings via a forged request …

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 22, 2026, 6:15 a.m.

6.1

CVSS3.1

CVE-2025-12400 - LMB^Box Smileys <= 3.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on the manage_page() function. This makes it possible for unauthenticated attackers to update settings and inject mali…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 22, 2026, noon

6.4

CVSS3.1

CVE-2025-12369 - Extensions for Leaflet Map <= 4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `geojsonmarker` shortcode in all versions up to, and including, 4.7. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for au…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 22, 2026, noon

7.5

CVSS3.1

CVE-2025-11890 - Crypto Payment Gateway with Payeer for WooCommerce <= 1.0.3 - Unauthenticated Payment Bypass

The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a payments status through server-side validation though the /wc-api/bp-payeer-gateway-callback en…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 22, 2026, 12:45 p.m.

5.3

CVSS3.1

CVE-2025-12157 - Simple User Capabilities <= 1.0 - Missing Authorization to Unauthenticated Capability Reset

The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_reset_capability' AJAX endpoint in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to reset any …

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 22, 2026, 12:15 p.m.

6.1

CVSS3.1

CVE-2025-12410 - SH Contextual Help <= 3.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation in the sh_contextual_help_dashboard_widget() function. This makes it possible for unauthenticated attackers to up…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 22, 2026, noon

6.5

CVSS3.1

CVE-2025-11758 - All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0.3 - Missing Author…

The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization check in all versions up to, and including, 2.0.3. This is due to the plugin exposing admin-level AJAX actions to unauthenticated users via wp_ajax_nopriv_ hooks, while relying o…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-12413 - Social Media WPCF7 Stop Words <= 1.1.3 - Cross-Site Request Forgery to Settings Update

The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the smWpCfSwOptions() function. This makes it possible for unauthenticated attackers to update the …

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 22, 2026, 4:45 p.m.
Total resulsts: 349182
Page 3160 of 34,919
Β« previous page Β» next page
Filters