6.4

CVSS3.1

CVE-2025-10140 - Quick Social Login <= 1.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Quick Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quick-login' shortcode in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 21, 2026, 2:30 a.m.

5.3

CVSS3.1

CVE-2025-11692 - Zip Attachments <= 1.6 - Missing Authorization to Limited File Deletion

The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the curren…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 21, 2026, 2:30 a.m.

6.5

CVSS3.1

CVE-2025-11365 - WP Google Map Plugin <= 1.0 - Authenticated (Contributor+) SQL Injection

The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google_map' shortcode in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 21, 2026, 2:30 a.m.

4.3

CVSS3.1

CVE-2025-10303 - Library Management System <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Settings Ma…

The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the owt7_library_management_ajax_handler() function in all versions up to, and including, 3.1. This makes it possible for authenticated attackers, with Subscrib…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 5 p.m.

4.3

CVSS3.1

CVE-2025-10312 - Theme Importer <= 1.0 - Cross-Site Request Forgery

The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation when processing form submissions in the theme-importer.php file. This makes it possible for unauthenticated attackers to trigger arb…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 1:15 p.m.

4.3

CVSS3.1

CVE-2025-10300 - TopBar <= 1.0.0 - Cross-Site Request Forgery to Settings Update

The TopBar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the fme_nb_topbar_save_settings() function. This makes it possible for unauthenticated attackers to update the plugin's se…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 1:15 p.m.

6.4

CVSS3.1

CVE-2025-10135 - WP ViewSTL <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP ViewSTL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewstl' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 1:15 p.m.

6.5

CVSS3.1

CVE-2025-10038 - Binary MLM Plan <= 3.0 - Unauthenticated Limited Privilege Escalation

The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users with the manage_bmp capability by default upon registration through the plugin's form. This makes it possible for unauthe…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 1:15 p.m.

6.4

CVSS3.1

CVE-2025-10132 - Dhivehi Text <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Dhivehi Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dhivehi' shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-10743 - Outdoor <= 1.3.2 - Unauthenticated SQL Injection

The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and including, 1.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated att…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 5 p.m.
Total resulsts: 349182
Page 3408 of 34,919
« previous page » next page
Filters