6.5

CVSS3.1

CVE-2025-57932 - WordPress PowerFolio Plugin <= 3.2.1 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Diego Pereira PowerFolio portfolio-elementor allows Stored XSS.This issue affects PowerFolio: from n/a through <= 3.2.1.

πŸ“… Published: Sept. 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

4.3

CVSS3.1

CVE-2025-57933 - WordPress Piotnet Forms Plugin <= 1.0.30 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in piotnetdotcom Piotnet Forms piotnetforms allows Cross Site Request Forgery.This issue affects Piotnet Forms: from n/a through <= 1.0.30.

πŸ“… Published: Sept. 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

4.3

CVSS3.1

CVE-2025-57934 - WordPress LWS Affiliation Plugin <= 2.3.6 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in AurΓ©lien LWS LWS Affiliation lws-affiliation allows Cross Site Request Forgery.This issue affects LWS Affiliation: from n/a through <= 2.3.6.

πŸ“… Published: Sept. 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.9

CVSS3.1

CVE-2025-57935 - WordPress Bot Block – Stop Spam Referrals in Google Analytics Plugin <= 2.6 - Cross Site Scripting …

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ricky Dawn Bot Block &#8211; Stop Spam Referrals in Google Analytics bot-block-stop-spam-google-analytics-referrals allows Stored XSS.This issue affects Bot Block &#8211; Stop Spam Referrals in Goo…

πŸ“… Published: Sept. 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

4.3

CVSS3.1

CVE-2025-57936 - WordPress Subresource Integrity (SRI) Manager Plugin <= 0.4.0 - Broken Access Control Vulnerability

Missing Authorization vulnerability in Meitar Subresource Integrity (SRI) Manager wp-sri allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subresource Integrity (SRI) Manager: from n/a through <= 0.4.0.

πŸ“… Published: Sept. 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

4.3

CVSS3.1

CVE-2025-57937 - WordPress WPeMatico RSS Feed Fetcher Plugin <= 2.8.10 - Sensitive Data Exposure Vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in etruel WPeMatico RSS Feed Fetcher wpematico allows Retrieve Embedded Sensitive Data.This issue affects WPeMatico RSS Feed Fetcher: from n/a through <= 2.8.10.

πŸ“… Published: Sept. 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-57938 - WordPress Easy Hotel Booking plugin <= 1.9.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themewant Easy Hotel Booking easy-hotel allows DOM-Based XSS.This issue affects Easy Hotel Booking: from n/a through <= 1.9.2.

πŸ“… Published: Sept. 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.3

CVSS3.1

CVE-2025-57939 - WordPress Image Hover Effects – Elementor Addon Plugin <= 1.4.4 - Broken Access Control Vulnerabili…

Missing Authorization vulnerability in Blocksera Image Hover Effects – Elementor Addon image-hover-effects-addon-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Hover Effects – Elementor Addon: from n/a through <= 1.4.4.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.9

CVSS3.1

CVE-2025-57940 - WordPress Append extensions on Pages Plugin <= 1.1.2 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh Kumar Mukhiya Append extensions on Pages append-extensions-on-pages allows Stored XSS.This issue affects Append extensions on Pages: from n/a through <= 1.1.2.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.9

CVSS3.1

CVE-2025-57941 - WordPress Append Link on Copy Plugin <= 0.2 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JonathanMH Append Link on Copy append-link-on-copy allows Stored XSS.This issue affects Append Link on Copy: from n/a through <= 0.2.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.
Total resulsts: 349182
Page 3729 of 34,919
Β« previous page Β» next page
Filters