5.3

CVSS3.1

CVE-2025-12350 - DominoKit <= 1.1.0 - Missing Authorization to Unauthenticated Settings Update

The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admin_action AJAX endpoint in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update plugin settings.

๐Ÿ“… Published: Nov. 4, 2025, 4:27 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2025-12393 - Free Quotation <= 3.1.6 - Authenticated (Admin+) Stored Cross-Site Scripting

The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions anโ€ฆ

๐Ÿ“… Published: Nov. 4, 2025, 4:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 4:45 p.m.

6.1

CVSS3.1

CVE-2025-12416 - Pagerank Tools <= 1.1.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the pr_save_settings() function and insufficient input sanitization. This makes it possible forโ€ฆ

๐Ÿ“… Published: Nov. 4, 2025, 4:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:30 p.m.

8.8

CVSS3.1

CVE-2025-10896 - Multiple Plugins <= Multiple Versions - Missing Authorization to Authenticated (Subscriber+) Arbitrโ€ฆ

Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of File with Dangerous Type via arbitrary plugin installation in all versions up to, and including, 1.0.2.3. This is due to missing capability checks on the '*_recommended_upgrade_pโ€ฆ

๐Ÿ“… Published: Nov. 4, 2025, 4:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:30 p.m.

6.1

CVSS3.1

CVE-2025-12412 - Top Bar Notification <= 1.12 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation on th tbn_ajax_add() function. This makes it possible for unauthenticated attackers to update the plugin's settiโ€ฆ

๐Ÿ“… Published: Nov. 4, 2025, 4:27 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-12188 - Posts Navigation Links for Sections and Headings - Free by WP Masters <= 1.0.1 - Cross-Site Requestโ€ฆ

The Posts Navigation Links for Sections and Headings โ€“ Free by WP Masters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the 'wpm_navigation_links_settings' page. This makes it posโ€ฆ

๐Ÿ“… Published: Nov. 4, 2025, 4:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 4:45 p.m.

5.8

CVSS4.0

CVE-2025-12683 - NULL DACL assigned to Named Pipe communicating with SYSTEM Service

The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained wโ€ฆ

๐Ÿ“… Published: Nov. 4, 2025, 4:23 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-12069 - WP Global Screen Options <= 0.2 - Cross-Site Request Forgery to Screen Options Update

The WP Global Screen Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing nonce validation on the `updatewpglobalscreenoptions` action handler. This makes it possible for unauthenticated attackers to modify globalโ€ฆ

๐Ÿ“… Published: Nov. 4, 2025, 3:26 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 12:45 a.m.

9.8

CVSS3.1

CVE-2025-11008 - CE21 Suite <= 2.3.1 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the log file. This makes it possible for unauthenticated attackers to extract sensitive data including authentication credentials, which can be used to log in as otherโ€ฆ

๐Ÿ“… Published: Nov. 4, 2025, 3:26 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 12:45 p.m.

6.1

CVSS3.1

CVE-2025-12401 - Label Plugins <= 0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Label Plugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect nonce validation on the label_plugins_options() function. This makes it possible for unauthenticated attackers to update settings and injโ€ฆ

๐Ÿ“… Published: Nov. 4, 2025, 3:26 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, noon
Total resulsts: 349182
Page 3161 of 34,919
ยซ previous page ยป next page
Filters