6.5

CVSS3.1

CVE-2025-59553 - WordPress Custom iFrame for Elementor Plugin <= 1.0.13 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coderz Studio Custom iFrame for Elementor custom-iframe allows DOM-Based XSS.This issue affects Custom iFrame for Elementor: from n/a through <= 1.0.13.

πŸ“… Published: Sept. 22, 2025, 6:26 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

4.3

CVSS3.1

CVE-2025-59559 - WordPress Payrexx Payment Gateway for WooCommerce Plugin <= 3.1.5 - Broken Access Control Vulnerabi…

Missing Authorization vulnerability in payrexx Payrexx Payment Gateway for WooCommerce woo-payrexx-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payrexx Payment Gateway for WooCommerce: from n/a through <= 3.1.5.

πŸ“… Published: Sept. 22, 2025, 6:26 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

4.3

CVSS3.1

CVE-2025-59561 - WordPress Smart Blocks Plugin <= 2.4 - Broken Access Control Vulnerability

Missing Authorization vulnerability in hashthemes Smart Blocks smart-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Blocks: from n/a through <= 2.4.

πŸ“… Published: Sept. 22, 2025, 6:26 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.5

CVSS3.1

CVE-2025-59562 - WordPress Academy LMS Plugin <= 3.3.4 - Insecure Direct Object References (IDOR) Vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Academy LMS: from n/a through <= 3.3.4.

πŸ“… Published: Sept. 22, 2025, 6:26 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

6.5

CVSS3.1

CVE-2025-59565 - WordPress Upsell Order Bump Offer for WooCommerce Plugin <= 3.0.7 - Cross Site Scripting (XSS) Vuln…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Upsell Order Bump Offer for WooCommerce upsell-order-bump-offer-for-woocommerce allows Stored XSS.This issue affects Upsell Order Bump Offer for WooCommerce: from n/a through <= 3.0.7.

πŸ“… Published: Sept. 22, 2025, 6:26 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

4.3

CVSS3.1

CVE-2025-59567 - WordPress Coupon Affiliates Plugin <= 6.8.0 - Broken Access Control Vulnerability

Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coupon Affiliates: from n/a through <= 6.8.0.

πŸ“… Published: Sept. 22, 2025, 6:26 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

4.3

CVSS3.1

CVE-2025-59568 - WordPress Zoho Flow Plugin <= 2.14.1 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Zoho Flow Zoho Flow zoho-flow allows Cross Site Request Forgery.This issue affects Zoho Flow: from n/a through <= 2.14.1.

πŸ“… Published: Sept. 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

6.5

CVSS3.1

CVE-2025-59569 - WordPress CubeWP Plugin <= 1.1.26 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Stored XSS.This issue affects CubeWP: from n/a through <= 1.1.26.

πŸ“… Published: Sept. 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

7.6

CVSS3.1

CVE-2025-59570 - WordPress Mail Mint Plugin <= 1.18.6 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Mint mail-mint allows SQL Injection.This issue affects Mail Mint: from n/a through <= 1.18.6.

πŸ“… Published: Sept. 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

8.8

CVSS3.1

CVE-2025-59572 - WordPress WorkScout-Core Plugin < 1.7.06 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Cross Site Request Forgery.This issue affects WorkScout-Core: from n/a through < 1.7.06.

πŸ“… Published: Sept. 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.
Total resulsts: 349182
Page 3721 of 34,919
Β« previous page Β» next page
Filters