7.2

CVSS3.1

CVE-2025-11995 - Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting

The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr…

πŸ“… Published: Nov. 1, 2025, 4:27 a.m. πŸ”„ Last Modified: April 22, 2026, 12:15 p.m.

4.3

CVSS3.1

CVE-2025-11377 - List category posts <= 0.92.0 - Authenticated (Contributor+) Information Exposure

The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.92.0 via the 'catlist' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with contributor-level acc…

πŸ“… Published: Nov. 1, 2025, 4:27 a.m. πŸ”„ Last Modified: April 22, 2026, 12:45 p.m.

4.4

CVSS3.1

CVE-2025-11928 - CSS & JavaScript Toolbox <= 12.0.5 - Authenticated (Admin+) Stored Cross-Site Scripting

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 12.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level per…

πŸ“… Published: Nov. 1, 2025, 3:34 a.m. πŸ”„ Last Modified: April 21, 2026, 2 a.m.

4.3

CVSS3.1

CVE-2025-12367 - SiteSEO – SEO Simplified <= 1.3.1 - Missing Authorization to Authenticated (Author+) Plugin Setting…

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.3.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Author-level ac…

πŸ“… Published: Nov. 1, 2025, 3:34 a.m. πŸ”„ Last Modified: April 22, 2026, noon

9.8

CVSS3.1

CVE-2025-11833 - Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing A…

The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and including, 3.6.0. This makes it possible for unauthenticated …

πŸ“… Published: Nov. 1, 2025, 3:34 a.m. πŸ”„ Last Modified: April 22, 2026, 2 p.m.

6.9

CVSS4.0

CVE-2025-62275 -

Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to…

πŸ“… Published: Nov. 1, 2025, 2:42 a.m. πŸ”„ Last Modified: Nov. 10, 2025, 4:20 p.m.

6.4

CVSS3.1

CVE-2025-11922 - Inactive Logout <= 3.5.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individual_user' parameter in all versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit…

πŸ“… Published: Nov. 1, 2025, 1:47 a.m. πŸ”„ Last Modified: April 21, 2026, 2 a.m.

8.8

CVSS3.1

CVE-2025-11920 - WPCOM Member <= 1.7.14 - Authenticated (Contributor+) Local File Inclusion via Shortcode

The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14 via the action parameter in one of its shortcodes. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .…

πŸ“… Published: Nov. 1, 2025, 1:47 a.m. πŸ”„ Last Modified: April 22, 2026, 1 p.m.

5.3

CVSS3.1

CVE-2025-11174 - Document Library Lite <= 1.1.6 - Missing Authorization to Sensitive Information Exposure

The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dll_load_posts which returns a JSON table of document data without performing nonce or capability che…

πŸ“… Published: Nov. 1, 2025, 1:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-11816 - Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.5.1 -…

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disconnect_account_request() function in all versions up to, and including, 3.5.1. This makes…

πŸ“… Published: Nov. 1, 2025, 1:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3186 of 34,919
Β« previous page Β» next page
Filters