6.4

CVSS3.1

CVE-2025-9077 - Ultra Addons Lite for Elementor <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Animated Text' field of the Typeout Widget in version 1.1.9 and below due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with c…

📅 Published: Oct. 3, 2025, 11:17 a.m. 🔄 Last Modified: April 21, 2026, 2:45 a.m.

9.8

CVSS3.1

CVE-2025-7721 - JoomSport <= 5.7.3 - Unauthenticated Directory Traversal to Local File Inclusion

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.7.3 via the task parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the s…

📅 Published: Oct. 3, 2025, 11:17 a.m. 🔄 Last Modified: April 21, 2026, 2:45 a.m.

5.5

CVSS3.1

CVE-2025-9332 - Interactive Medical Drawing of Human Body <= 2.6 - Authenticated (Admin+) Stored Cross-Site Scripti…

The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

📅 Published: Oct. 3, 2025, 11:17 a.m. 🔄 Last Modified: April 21, 2026, 2:45 a.m.

6.4

CVSS3.1

CVE-2025-9876 - Ird Slider <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ird Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irdslider' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack…

📅 Published: Oct. 3, 2025, 11:17 a.m. 🔄 Last Modified: April 21, 2026, 2:45 a.m.

6.4

CVSS3.1

CVE-2025-9875 - Event Tickets, RSVPs, Calendar <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Event Tickets, RSVPs, Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ticket_spot' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fo…

📅 Published: Oct. 3, 2025, 11:17 a.m. 🔄 Last Modified: April 21, 2026, 7 p.m.

6.5

CVSS3.1

CVE-2025-9198 - Wp cycle text announcement <= 8.1 - Authenticated (Contributor+) SQL Injection

The Wp cycle text announcement plugin for WordPress is vulnerable to SQL Injection via the 'cycle-text' shortcode in all versions up to, and including, 8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib…

📅 Published: Oct. 3, 2025, 11:17 a.m. 🔄 Last Modified: April 22, 2026, 4 a.m.

9.8

CVSS3.1

CVE-2025-9286 - Appy Pie Connect for WooCommerce <= 1.1.2 - Missing Authorization to Unauthenticated Privilege Esca…

The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to reset the password of ar…

📅 Published: Oct. 3, 2025, 11:17 a.m. 🔄 Last Modified: April 21, 2026, 7 p.m.

9.8

CVSS3.1

CVE-2025-9209 - RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to…

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due to the plugin exposing user private tokens and API data via the /wp-json/wp/v2/users REST API endpoint. This makes it possible for unauthenticated atta…

📅 Published: Oct. 3, 2025, 11:17 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-9885 - MPWizard – Create Mercado Pago Payment Links <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Pos…

The MPWizard – Create Mercado Pago Payment Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation in the '/includes/admin/class-mpwizard-table.php' file. This makes it possible for unau…

📅 Published: Oct. 3, 2025, 11:17 a.m. 🔄 Last Modified: April 22, 2026, 2:15 p.m.

5.5

CVSS3.1

CVE-2025-9333 - Smart Docs <= 1.1.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and ab…

📅 Published: Oct. 3, 2025, 11:17 a.m. 🔄 Last Modified: April 22, 2026, 5 p.m.
Total resulsts: 349182
Page 3583 of 34,919
« previous page » next page
Filters