6.4

CVSS3.1

CVE-2025-10129 - WordPress Live Webcam Widget & Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scโ€ฆ

The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibleโ€ฆ

๐Ÿ“… Published: Oct. 11, 2025, 9:28 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 12:45 a.m.

4.3

CVSS3.1

CVE-2025-10375 - Web Accessibility By accessiBe <= 2.10 - Cross-Site Request Forgery

The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10. This is due to missing nonce validation on multiple AJAX actions including accessibe_signup, accessibe_login, accessibe_license_trial, accessibe_modify_conโ€ฆ

๐Ÿ“… Published: Oct. 11, 2025, 9:28 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 2:30 a.m.

4.9

CVSS3.1

CVE-2025-9947 - Custom 404 Pro <= 3.12.0 - Authenticated (Administrator+) SQL Injection via `path` Parameter

The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the โ€˜pathโ€™ parameter in all versions up to, and including, 3.12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fโ€ฆ

๐Ÿ“… Published: Oct. 11, 2025, 9:28 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 9:45 p.m.

2.4

CVSS3.1

CVE-2025-8606 - GSheetConnector For Gravity Forms <= 1.3.23 - Cross-Site Request Forgery to Arbitrary Plugin Activaโ€ฆ

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 1.3.23. This is due to missing or incorrect nonce validation on the activate_plugin and deactivate_plugin functions. This makes it possible for attackers to triโ€ฆ

๐Ÿ“… Published: Oct. 11, 2025, 9:28 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:30 p.m.

6.5

CVSS3.1

CVE-2025-10175 - WP Links Page <= 4.9.6 - Authenticated (Subscriber+) SQL Injection

The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticateโ€ฆ

๐Ÿ“… Published: Oct. 11, 2025, 9:28 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 2:30 a.m.

8.8

CVSS3.1

CVE-2025-8593 - GSheetConnector For Gravity Forms <= 1.3.27 - Missing Authorization to Authenticated (Subscriber+) โ€ฆ

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is due to a missing capability check on the 'install_plugin' function. This makes it possible for authenticated attackers, with subscriber-level access aโ€ฆ

๐Ÿ“… Published: Oct. 11, 2025, 9:28 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:30 p.m.

5.3

CVSS3.1

CVE-2025-8484 - Code Quality Control Tool <= 2.1 - Unauthenticated Information Exposure via Log Files

The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

๐Ÿ“… Published: Oct. 11, 2025, 9:28 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:30 p.m.

4.9

CVSS3.1

CVE-2025-9950 - Error Log Viewer by BestWebSoft <= 1.1.6 - Authenticated (Administrator+) Arbitrary File Read

The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.6 via the rrrlgvwr_get_file function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrโ€ฆ

๐Ÿ“… Published: Oct. 11, 2025, 9:28 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 2:30 a.m.

4.3

CVSS3.1

CVE-2025-8682 - Newsup <= 5.0.10 - Missing Authorization to Authenticated (Subscriber+) Plugin Installation

The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the newsup_admin_info_install_plugin() function in all versions up to, and including, 5.0.10. This makes it possible for unauthenticated attackers to install the ansar-import plugin.

๐Ÿ“… Published: Oct. 11, 2025, 9:28 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 4 a.m.

4.3

CVSS3.1

CVE-2025-9626 - Page Blocks <= 1.1.0 - Cross-Site Request Forgery

The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the admin_process_widget_page_change function. This makes it possible for unauthenticated attackers to modify widget โ€ฆ

๐Ÿ“… Published: Oct. 11, 2025, 9:28 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 12:45 a.m.
Total resulsts: 349182
Page 3470 of 34,919
ยซ previous page ยป next page
Filters