6.5

CVSS3.1

CVE-2025-64194 - WordPress Eduma theme <= 5.7.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Eduma eduma allows Stored XSS.This issue affects Eduma: from n/a through <= 5.7.6.

πŸ“… Published: Oct. 29, 2025, 8:38 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-60075 - WordPress hpb seo plugin for WordPress plugin <= 3.0.1 - Cross Site Request Forgery (CSRF) vulnerab…

Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflected XSS.This issue affects hpb seo plugin for WordPress: from n/a through <= 3.0.1.

πŸ“… Published: Oct. 29, 2025, 8:38 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-58939 - WordPress Super Store Finder plugin <= 7.5 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site Request Forgery.This issue affects Super Store Finder: from n/a through <= 7.5.

πŸ“… Published: Oct. 29, 2025, 8:38 a.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.3

CVSS3.1

CVE-2025-58711 - WordPress Blog Designer PRO plugin <= 3.4.8 - Broken Access Control vulnerability

Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blog Designer PRO: from n/a through <= 3.4.8.

πŸ“… Published: Oct. 29, 2025, 8:38 a.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

8.5

CVSS3.1

CVE-2025-11702 - Missing Authorization in GitLab

GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker with specific permissions to hijack project runners from other projects.

πŸ“… Published: Oct. 29, 2025, 7:04 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

5.3

CVSS3.1

CVE-2023-7320 - WooCommerce <= 7.8.2 - Sensitive Information Exposure

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitiv…

πŸ“… Published: Oct. 29, 2025, 6:45 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-9544 - Doppler Forms <= 2.5.1 - Subscriber+ Limited Plugin Installation

The Doppler Forms WordPress plugin through 2.5.1 registers an AJAX action install_extension without verifying user capabilities or using a nonce. As a result, any authenticated user β€” including those with the Subscriber role β€” can install and activate additional Doppler Forms WordPress plugin throu…

πŸ“… Published: Oct. 29, 2025, 6 a.m. πŸ”„ Last Modified: April 27, 2026, 11:45 p.m.

5.9

CVSS3.1

CVE-2025-49042 - WordPress WooCommerce plugin <= 10.0.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n/a through <= 10.0.2.

πŸ“… Published: Oct. 29, 2025, 4:50 a.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

8.4

CVSS4.0

CVE-2025-62776 -

The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.

πŸ“… Published: Oct. 29, 2025, 4:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-11705 - Anti-Malware Security and Brute-Force Firewall <= 4.23.81 - Missing Authorization to Authenticated …

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.23.81 due to a missing capability check combined with an information exposure in several GOTMLS_* AJAX actions. This makes it possible for authenticat…

πŸ“… Published: Oct. 29, 2025, 4:27 a.m. πŸ”„ Last Modified: April 21, 2026, 2:15 a.m.
Total resulsts: 349182
Page 3231 of 34,919
Β« previous page Β» next page
Filters