4.3

CVSS3.1

CVE-2025-57992 - WordPress Mail Baby SMTP plugin <= 2.8 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in InterServer Mail Baby SMTP mail-baby-smtp allows Cross Site Request Forgery.This issue affects Mail Baby SMTP: from n/a through <= 2.8.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-57993 - WordPress Geolocation IP Detection plugin <= 5.5.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Pick Geolocation IP Detection geoip-detect allows Stored XSS.This issue affects Geolocation IP Detection: from n/a through <= 5.5.0.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.4

CVSS3.1

CVE-2025-57994 - WordPress Upcoming Events Lists Plugin <= 1.4.0 - Insecure Direct Object References (IDOR) Vulnerab…

Authorization Bypass Through User-Controlled Key vulnerability in Sayful Islam Upcoming Events Lists upcoming-events-lists allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Upcoming Events Lists: from n/a through <= 1.4.0.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

4.3

CVSS3.1

CVE-2025-57995 - WordPress DethemeKit For Elementor Plugin <= 2.1.10 - Broken Access Control Vulnerability

Missing Authorization vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DethemeKit For Elementor: from n/a through <= 2.1.10.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-57996 - WordPress Buckets Plugin <= 0.3.9 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matthewordie Buckets buckets allows Stored XSS.This issue affects Buckets: from n/a through <= 0.3.9.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

4.3

CVSS3.1

CVE-2025-57997 - WordPress Trustpilot Reviews Plugin <= 2.5.925 - Broken Access Control Vulnerability

Missing Authorization vulnerability in Trustpilot Trustpilot Reviews trustpilot-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trustpilot Reviews: from n/a through <= 2.5.925.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.9

CVSS3.1

CVE-2025-57998 - WordPress E-namad & Shamed Logo Manager Plugin <= 2.2 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hamid Reza Yazdani E-namad &amp; Shamed Logo Manager e-namad-shamed-logo-manager allows Stored XSS.This issue affects E-namad &amp; Shamed Logo Manager: from n/a through <= 2.2.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-57999 - WordPress WPKoi Templates for Elementor Plugin <= 3.4.3 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpkoithemes WPKoi Templates for Elementor wpkoi-templates-for-elementor allows DOM-Based XSS.This issue affects WPKoi Templates for Elementor: from n/a through <= 3.4.3.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.3

CVSS3.1

CVE-2025-58000 - WordPress Memberful plugin <= 1.75.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in memberful Memberful - Membership Plugin memberful-wp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberful - Membership Plugin: from n/a through <= 1.75.0.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-58001 - WordPress Compact Archives plugin <= 4.1.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Compact Archives compact-archives allows Stored XSS.This issue affects Compact Archives: from n/a through <= 4.1.0.

πŸ“… Published: Sept. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.
Total resulsts: 349182
Page 3735 of 34,919
Β« previous page Β» next page
Filters