8.8
CVE-2025-62007 - WordPress Voice Feedback plugin <= 1.0.3 - Privilege Escalation vulnerability
Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback: from n/a through <= 1.0.3.
5.4
CVE-2025-62006 - WordPress WP SMS plugin <= 7.0.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in VeronaLabs WP SMS wp-sms.This issue affects WP SMS: from n/a through <= 7.0.1.
7.1
CVE-2025-62005 - WordPress SUMO Memberships for WooCommerce plugin < 7.8.0 - Cross Site Request Forgery (CSRF) vulneβ¦
Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Cross Site Request Forgery.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0.
7.1
CVE-2025-60246 - WordPress Simple Finance Calculator plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerabilβ¦
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weissmike Simple Finance Calculator simple-finance-calculator allows Reflected XSS.This issue affects Simple Finance Calculator: from n/a through <= 1.0.
9.8
CVE-2025-60238 - WordPress UNIVERSAM plugin <= 9.04.02 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in universam UNIVERSAM universam-demo allows Object Injection.This issue affects UNIVERSAM: from n/a through <= 9.04.02.
8.8
CVE-2025-60234 - WordPress Single Property theme <= 2.8 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.This issue affects Single Property: from n/a through <= 2.8.
9.8
CVE-2025-60232 - WordPress KBx Pro Ultimate plugin <= 8.0.5 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Object Injection.This issue affects KBx Pro Ultimate: from n/a through <= 8.0.5.
8.8
CVE-2025-60228 - WordPress Knowledge Base theme <= 2.9 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9.
8.6
CVE-2025-60227 - WordPress WP Pipes plugin <= 1.4.3 - Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pipes allows Path Traversal.This issue affects WP Pipes: from n/a through <= 1.4.3.
9.8
CVE-2025-60226 - WordPress White Rabbit theme <= 1.5.2 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in axiomthemes White Rabbit whiterabbit allows Object Injection.This issue affects White Rabbit: from n/a through <= 1.5.2.