6.5

CVSS3.1

CVE-2025-62912 - WordPress SiteGround Email Marketing plugin <= 1.7.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.1.

πŸ“… Published: Oct. 27, 2025, 1:33 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

6.5

CVSS3.1

CVE-2025-62911 - WordPress Rock Convert plugin <= 3.0.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Content Rock Convert rock-convert allows Stored XSS.This issue affects Rock Convert: from n/a through <= 3.0.1.

πŸ“… Published: Oct. 27, 2025, 1:33 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

6.5

CVSS3.1

CVE-2025-62910 - WordPress Video Gallery by Huzzaz plugin <= 10.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in deshine Video Gallery by Huzzaz huzzaz-video-gallery allows Stored XSS.This issue affects Video Gallery by Huzzaz: from n/a through <= 10.5.

πŸ“… Published: Oct. 27, 2025, 1:33 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

4.3

CVSS3.1

CVE-2025-62909 - WordPress Smart WeTransfer plugin <= 1.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in mrityunjay Smart WeTransfer smart-wetransfer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart WeTransfer: from n/a through <= 1.3.

πŸ“… Published: Oct. 27, 2025, 1:33 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

9.8

CVSS3.1

CVE-2025-62908 - WordPress Podlove Web Player plugin <= 5.9.1 - Broken Access Control vulnerability

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Oct. 27, 2025, 1:33 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 8:16 a.m.

6.5

CVSS3.1

CVE-2025-62907 - WordPress Custom Post Type Attachment plugin <= 3.4.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Custom Post Type Attachment custom-post-type-pdf-attachment allows Stored XSS.This issue affects Custom Post Type Attachment: from n/a through <= 3.4.6.

πŸ“… Published: Oct. 27, 2025, 1:33 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

4.3

CVSS3.1

CVE-2025-62906 - WordPress Referral Link Tracker plugin <= 1.1.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in epiphanyit321 Referral Link Tracker referral-link-tracker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Referral Link Tracker: from n/a through <= 1.1.4.

πŸ“… Published: Oct. 27, 2025, 1:33 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

6.5

CVSS3.1

CVE-2025-62905 - WordPress Query Posts plugin <= 0.3.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Query Posts query-posts allows Stored XSS.This issue affects Query Posts: from n/a through <= 0.3.2.

πŸ“… Published: Oct. 27, 2025, 1:33 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

6.5

CVSS3.1

CVE-2025-62904 - WordPress WP Geo plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ben Huson WP Geo wp-geo allows Stored XSS.This issue affects WP Geo: from n/a through <= 3.5.1.

πŸ“… Published: Oct. 27, 2025, 1:33 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

6.5

CVSS3.1

CVE-2025-62903 - WordPress WPC Smart Messages for WooCommerce plugin <= 4.2.8 - Cross Site Scripting (XSS) vulnerabi…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPClever WPC Smart Messages for WooCommerce wpc-smart-messages allows Stored XSS.This issue affects WPC Smart Messages for WooCommerce: from n/a through <= 4.2.8.

πŸ“… Published: Oct. 27, 2025, 1:33 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.
Total resulsts: 349182
Page 3275 of 34,919
Β« previous page Β» next page
Filters