6.4
CVE-2025-10194 - Shortcode Button <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Shortcode Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…
5.3
CVE-2025-11701 - Zip Attachments <= 1.6 - Missing Authorization to Unauthenticated Private And Password-Protected Po…
The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post status validation in the za_create_zip_callback function in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to…
6.4
CVE-2025-10141 - Digiseller <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Digiseller plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ds' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
4.4
CVE-2025-10056 - Task Scheduler <= 1.6.3 - Authenticated (Admin+) Blind Server-Side Request Forgery
The Task Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.3 via the “Check Website” task. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations o…
5.3
CVE-2025-11728 - Oceanpayment CreditCard Gateway <= 6.0 - Missing Authentication to Unauthenticated Order Status Upd…
The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'return_payment' and 'notice_payment' functions in all versions up to, and including, 6.0. This makes it possibl…
7.2
CVE-2025-10313 - Find And Replace content for WordPress <= 1.1 - Missing Authorization to Unauthenticated Stored Cro…
The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scripting and Arbitrary Content Replacement due to a missing capability check on the far_admin_ajax_fun() function in all versions up to, and including, 1.1. This makes it possible for un…
4.3
CVE-2025-11196 - External Login <= 1.11.2 - Authenticated (Subscriber+) Sensitive Data Exposure via Test Connection
The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.11.2 due to the 'exlog_test_connection' AJAX action lacking capability checks or nonce validation. This makes it possible for authenticated attackers, with subscriber-leve…
5.3
CVE-2025-10486 - Content Writer <= 3.6.8 - Unauthenticated Information Exposure via Log File
The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.8 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.
9.8
CVE-2025-10294 - OwnID Passwordless Login <= 1.3.4 - Authentication Bypass
The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthen…
9.8
CVE-2025-9967 - Orion SMS OTP Verification <= 1.1.7 - Authentication Bypass via Account Takeover
The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticate…