6.4

CVSS3.1

CVE-2025-10194 - Shortcode Button <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Shortcode Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

📅 Published: Oct. 15, 2025, 8:26 a.m. 🔄 Last Modified: April 21, 2026, 7 p.m.

5.3

CVSS3.1

CVE-2025-11701 - Zip Attachments <= 1.6 - Missing Authorization to Unauthenticated Private And Password-Protected Po…

The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post status validation in the za_create_zip_callback function in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to…

📅 Published: Oct. 15, 2025, 8:26 a.m. 🔄 Last Modified: April 21, 2026, 2:30 a.m.

6.4

CVSS3.1

CVE-2025-10141 - Digiseller <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Digiseller plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ds' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…

📅 Published: Oct. 15, 2025, 8:26 a.m. 🔄 Last Modified: April 21, 2026, 7 p.m.

4.4

CVSS3.1

CVE-2025-10056 - Task Scheduler <= 1.6.3 - Authenticated (Admin+) Blind Server-Side Request Forgery

The Task Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.3 via the “Check Website” task. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations o…

📅 Published: Oct. 15, 2025, 8:26 a.m. 🔄 Last Modified: April 21, 2026, 2:30 a.m.

5.3

CVSS3.1

CVE-2025-11728 - Oceanpayment CreditCard Gateway <= 6.0 - Missing Authentication to Unauthenticated Order Status Upd…

The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'return_payment' and 'notice_payment' functions in all versions up to, and including, 6.0. This makes it possibl…

📅 Published: Oct. 15, 2025, 8:26 a.m. 🔄 Last Modified: April 21, 2026, 2:30 a.m.

7.2

CVSS3.1

CVE-2025-10313 - Find And Replace content for WordPress <= 1.1 - Missing Authorization to Unauthenticated Stored Cro…

The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scripting and Arbitrary Content Replacement due to a missing capability check on the far_admin_ajax_fun() function in all versions up to, and including, 1.1. This makes it possible for un…

📅 Published: Oct. 15, 2025, 8:26 a.m. 🔄 Last Modified: April 21, 2026, 2:30 a.m.

4.3

CVSS3.1

CVE-2025-11196 - External Login <= 1.11.2 - Authenticated (Subscriber+) Sensitive Data Exposure via Test Connection

The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.11.2 due to the 'exlog_test_connection' AJAX action lacking capability checks or nonce validation. This makes it possible for authenticated attackers, with subscriber-leve…

📅 Published: Oct. 15, 2025, 8:26 a.m. 🔄 Last Modified: April 21, 2026, 7 p.m.

5.3

CVSS3.1

CVE-2025-10486 - Content Writer <= 3.6.8 - Unauthenticated Information Exposure via Log File

The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.8 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

📅 Published: Oct. 15, 2025, 8:26 a.m. 🔄 Last Modified: April 21, 2026, 7 p.m.

9.8

CVSS3.1

CVE-2025-10294 - OwnID Passwordless Login <= 1.3.4 - Authentication Bypass

The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthen…

📅 Published: Oct. 15, 2025, 8:26 a.m. 🔄 Last Modified: April 21, 2026, 2:30 a.m.

9.8

CVSS3.1

CVE-2025-9967 - Orion SMS OTP Verification <= 1.1.7 - Authentication Bypass via Account Takeover

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticate…

📅 Published: Oct. 15, 2025, 8:26 a.m. 🔄 Last Modified: April 20, 2026, 9:45 p.m.
Total resulsts: 349182
Page 3407 of 34,919
« previous page » next page
Filters