4.9

CVSS3.1

CVE-2025-9345 - File Manager, Code Editor, and Backup by Managefy <= 1.4.8 - Authenticated (Admin+) Path Traversal …

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.8 via the ajax_downloadfile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions…

📅 Published: Aug. 28, 2025, 3:42 a.m. 🔄 Last Modified: Aug. 28, 2025, 3:42 a.m.

6.4

CVSS3.1

CVE-2025-9346 - Booking Calendar <= 10.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 10.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above…

📅 Published: Aug. 28, 2025, 3:42 a.m. 🔄 Last Modified: Aug. 28, 2025, 3:42 a.m.

6.1

CVSS3.1

CVE-2024-9648 - WP ULike Pro <= 1.9.3 - Unauthenticated Limited Arbitrary File Upload

The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the WP_Ulike_Pro_File_Uploader class in all versions up to, and including, 1.9.3. This makes it possible for unauthenticated attackers to upload limited arbitrary files like .ph…

📅 Published: Aug. 28, 2025, 3:42 a.m. 🔄 Last Modified: Aug. 28, 2025, 3:42 a.m.

6.4

CVSS3.1

CVE-2025-8603 - Unlimited Elements For Elementor <= 1.5.148 - Authenticated (Contributor+) Stored Cross-Site Script…

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.148 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l…

📅 Published: Aug. 28, 2025, 3:42 a.m. 🔄 Last Modified: Aug. 28, 2025, 3:42 a.m.

4.3

CVSS3.1

CVE-2025-0951 - LiquidThemes Themes <= Various Versions - Missing Authorization to Authenticated (Subscriber+) All …

Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactiva…

📅 Published: Aug. 28, 2025, 3:42 a.m. 🔄 Last Modified: Aug. 28, 2025, 3:42 a.m.

7.5

CVSS3.1

CVE-2025-36003 - IBM Security Verify Governance Identity Manager information disclosure

IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.

📅 Published: Aug. 28, 2025, 2:07 a.m. 🔄 Last Modified: Aug. 28, 2025, 2:07 a.m.

8.8

CVSS3.1

CVE-2025-7812 - Video Share VOD – Turnkey Video Site Builder Script <= 2.7.6 - Cross-Site Request Forgery to Comman…

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.6. This is due to missing or incorrect nonce validation on the adminExport() function. This makes it possible for unauthenticated attack…

📅 Published: Aug. 28, 2025, 1:46 a.m. 🔄 Last Modified: Aug. 28, 2025, 1:46 a.m.

6.1

CVSS3.1

CVE-2025-8897 - Beaver Builder Plugin (Lite Version) <= 2.9.2.1 - Reflected Cross-Site Scripting

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'fl_builder' parameter in all versions up to, and including, 2.9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attac…

📅 Published: Aug. 28, 2025, 1:46 a.m. 🔄 Last Modified: Aug. 28, 2025, 1:46 a.m.

6.4

CVSS3.1

CVE-2025-9344 - UsersWP <= 1.2.42 - Authenticated (Contributor+) Stored Cross-Site Scripting

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uwp_profile' and 'uwp_profile_header' shortcodes in all versions up to, and including, 1.2.42 due to insufficient…

📅 Published: Aug. 28, 2025, 1:46 a.m. 🔄 Last Modified: Aug. 28, 2025, 1:46 a.m.

5.4

CVSS3.1

CVE-2025-9352 - Pronamic Google Maps <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Pronamic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acc…

📅 Published: Aug. 28, 2025, 1:46 a.m. 🔄 Last Modified: Aug. 28, 2025, 1:46 a.m.
Total resulsts: 307515
Page 34 of 30,752
« previous page » next page
Filters