4.3

CVSS3.1

CVE-2025-11519 - Image optimization service by Optimole <= 4.1.0 - Insecure Direct Object Reference to Authenticated…

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the /wp-json/optml/v1/move_image REST API endpoint due to missing validation on a user c…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-11510 - FileBird <= 6.4.9 - Improper Authorization to Authenticated (Author+) Settings Reset

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /filebird/v1/fb-wipe-clear-all-data function in all versions up to, and including, 6.4.9. This makes it possible for authent…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 22, 2026, 12:45 p.m.

6.4

CVSS3.1

CVE-2025-9562 - Redirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 21, 2026, 2:15 a.m.

5.3

CVSS3.1

CVE-2025-11703 - WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated att…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 22, 2026, 12:45 p.m.

6.4

CVSS3.1

CVE-2025-10006 - WPBakery Page Builder <= 8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, 8.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 22, 2026, 1:15 p.m.

4.9

CVSS3.1

CVE-2025-10187 - GSpeech TTS – WordPress Text To Speech Plugin <= 3.17.13 - Authenticated (Admin+) SQL injection

The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' parameter in all versions up to, and including, 3.17.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 22, 2026, 1:15 p.m.

5.3

CVSS3.1

CVE-2025-11741 - WPC Smart Quick View for WooCommerce <= 4.2.5 - Insecure Direct Object Reference to Unauthenticated…

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attacke…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 22, 2026, 10 p.m.

7.5

CVSS3.1

CVE-2025-11517 - Event Tickets and Registration <= 5.26.5 - Unauthenticated Ticket Payment Bypass

The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to the /wp-json/tribe/tickets/v1/commerce/free/order endpoint not verifying that a ticket type should be free allowing the user to bypass the payment. Th…

📅 Published: Oct. 18, 2025, 6:42 a.m. 🔄 Last Modified: April 22, 2026, 10:15 p.m.

4.3

CVSS3.1

CVE-2025-11742 - WPC Smart Wishlist for WooCommerce <= 5.0.4 - Missing Authorization to Authenticated (Subscriber+) …

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' AJAX action in all versions up to, and including, 5.0.4. This makes it possible for authenticated attackers, with Subscriber-level a…

📅 Published: Oct. 18, 2025, 5:41 a.m. 🔄 Last Modified: April 22, 2026, 12:45 p.m.

6.4

CVSS3.1

CVE-2025-11857 - XX2WP Integration Tools <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

The XX2WP Integration Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mxp_fb2wp_display_embed' shortcode in all versions up to, and including, 1.9.9. This is due to the plugin not properly sanitizing user input and output of the 'post_id' parameter. This makes it po…

📅 Published: Oct. 18, 2025, 5:41 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3373 of 34,919
« previous page » next page
Filters