4.3

CVSS3.1

CVE-2025-54694 - WordPress Button Block Plugin plugin <= 1.2.0 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in bPlugins Button Block allows Cross Site Request Forgery. This issue affects Button Block: from n/a through 1.2.0.

๐Ÿ“… Published: Aug. 14, 2025, 10:34 a.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 10:34 a.m.

9

CVSS3.1

CVE-2025-54693 - WordPress Form Block Plugin <= 1.5.5 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in epiphyt Form Block allows Upload a Web Shell to a Web Server. This issue affects Form Block: from n/a through 1.5.5.

๐Ÿ“… Published: Aug. 14, 2025, 10:34 a.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 10:34 a.m.

7.5

CVSS3.1

CVE-2025-54692 - WordPress Membership For WooCommerce Plugin <= 2.9.0 - Broken Access Control Vulnerability

Missing Authorization vulnerability in WP Swings Membership For WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Membership For WooCommerce: from n/a through 2.9.0.

๐Ÿ“… Published: Aug. 14, 2025, 10:34 a.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 10:34 a.m.

5.3

CVSS3.1

CVE-2025-54691 - WordPress Motors Plugin plugin <= 1.4.80 - Insecure Direct Object References (IDOR) Vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Motors: from n/a through 1.4.80.

๐Ÿ“… Published: Aug. 14, 2025, 10:34 a.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 10:34 a.m.

8.1

CVSS3.1

CVE-2025-54690 - WordPress Xinterio Theme <= 4.2 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek Xinterio allows PHP Local File Inclusion. This issue affects Xinterio: from n/a through 4.2.

๐Ÿ“… Published: Aug. 14, 2025, 10:34 a.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 10:34 a.m.

8.1

CVSS3.1

CVE-2025-54689 - WordPress Urna Theme <= 2.5.7 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna allows PHP Local File Inclusion. This issue affects Urna: from n/a through 2.5.7.

๐Ÿ“… Published: Aug. 14, 2025, 10:34 a.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 10:34 a.m.

6.5

CVSS3.1

CVE-2025-54688 - WordPress JetEngine Plugin plugin <= 3.7.1.2 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.1.2.

๐Ÿ“… Published: Aug. 14, 2025, 10:34 a.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 10:34 a.m.

6.5

CVSS3.1

CVE-2025-54687 - WordPress JetTabs Plugin plugin <= 2.2.9.1 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs allows DOM-Based XSS. This issue affects JetTabs: from n/a through 2.2.9.1.

๐Ÿ“… Published: Aug. 14, 2025, 10:34 a.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 10:34 a.m.

9.8

CVSS3.1

CVE-2025-54686 - WordPress Exertio Theme <= 1.3.2 - PHP Object Injection Vulnerability

Deserialization of Untrusted Data vulnerability in scriptsbundle Exertio allows Object Injection. This issue affects Exertio: from n/a through 1.3.2.

๐Ÿ“… Published: Aug. 14, 2025, 10:34 a.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 10:34 a.m.

6.5

CVSS3.1

CVE-2025-54685 - WordPress SureDash Plugin <= 1.1.0 - Sensitive Data Exposure Vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Brainstorm Force SureDash allows Retrieve Embedded Sensitive Data. This issue affects SureDash: from n/a through 1.1.0.

๐Ÿ“… Published: Aug. 14, 2025, 10:34 a.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 10:34 a.m.
Total resulsts: 305870
Page 37 of 30,587
ยซ previous page ยป next page
Filters