6.4

CVSS3.1

CVE-2025-9130 - Unify <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via unify_checkout Shortc…

The Unify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's unify_checkout shortcode in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti…

πŸ“… Published: Oct. 3, 2025, 11:17 a.m. πŸ”„ Last Modified: April 22, 2026, 2:15 p.m.

9.1

CVSS3.1

CVE-2025-10726 - WPRecovery <= 2.0 - Unauthenticated SQL Injection to Arbitrary File Deletion

The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, and including, 2.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for una…

πŸ“… Published: Oct. 3, 2025, 11:17 a.m. πŸ”„ Last Modified: April 22, 2026, 10:15 p.m.

4.3

CVSS3.1

CVE-2025-10311 - Comment Info Detector <= 1.0.5 - Cross-Site Request Forgery to Settings Update

The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing nonce validation on the options.php file when handling form submissions. This makes it possible for unauthenticated attackers to modify plug…

πŸ“… Published: Oct. 3, 2025, 11:17 a.m. πŸ”„ Last Modified: April 22, 2026, 10:15 p.m.

6.4

CVSS3.1

CVE-2025-9045 - Easy Elementor Addons <= 2.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Easy Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in versions less than, or equal to, 2.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level …

πŸ“… Published: Oct. 3, 2025, 11:17 a.m. πŸ”„ Last Modified: April 22, 2026, 2:15 p.m.

5.3

CVSS3.1

CVE-2025-10212 - SiteAlert (Formerly WP Health) <= 1.9.8 - Missing Authorization to Unauthenticated Site Health Info…

The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and including, 1.9.8. This makes it possible for unauthenticated attackers to view the site health information, includi…

πŸ“… Published: Oct. 3, 2025, 11:17 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-9213 - TextBuilder 1.0.0 - 1.1.1 - Cross-Site Request Forgery to Privilege Escalation via Account Takeover

The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due to missing or incorrect nonce validation on the 'handleToken' function. This makes it possible for unauthenticated attackers to update a user's authorization token via a forged r…

πŸ“… Published: Oct. 3, 2025, 11:17 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-11249 -

This CVE id was assigned as a duplicate of CVE-2025-66414.

πŸ“… Published: Oct. 3, 2025, 8:59 a.m. πŸ”„ Last Modified: April 20, 2026, 6:52 p.m.

0.0

CVE-2025-61893 -

Not used

πŸ“… Published: Oct. 3, 2025, 8:50 a.m. πŸ”„ Last Modified: Oct. 4, 2025, 2:55 a.m.

0.0

CVE-2025-61892 -

Not used

πŸ“… Published: Oct. 3, 2025, 8:50 a.m. πŸ”„ Last Modified: Oct. 4, 2025, 2:55 a.m.

0.0

CVE-2025-61891 -

Not used

πŸ“… Published: Oct. 3, 2025, 8:50 a.m. πŸ”„ Last Modified: Oct. 4, 2025, 2:55 a.m.
Total resulsts: 349182
Page 3584 of 34,919
Β« previous page Β» next page
Filters