9.8

CVSS3.1

CVE-2025-8570 - BeyondCart Connector <= 3.0.1 - Missing Configuration of JWT Secret to Unauthenticated Privilege Es…

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 3.0.1. This makes it possible for unauthenticated attackers to craft valid tokens and assume…

📅 Published: Sept. 11, 2025, 7:24 a.m. 🔄 Last Modified: April 20, 2026, 10 p.m.

6.5

CVSS3.1

CVE-2025-9451 - Smartcat Translator for WPML <= 3.1.72 - Authenticated (Author+) SQL Injection via orderby Parameter

The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 3.1.72 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This ma…

📅 Published: Sept. 11, 2025, 7:24 a.m. 🔄 Last Modified: April 20, 2026, 7:45 p.m.

6.4

CVSS3.1

CVE-2025-8689 - Elements Plus! <= 2.16.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Wi…

The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, HotSpot Plus, and Google Maps widgets in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This mak…

📅 Published: Sept. 11, 2025, 7:24 a.m. 🔄 Last Modified: April 20, 2026, 7:45 p.m.

6.4

CVSS3.1

CVE-2025-8215 - Responsive Addons for Elementor <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

📅 Published: Sept. 11, 2025, 7:24 a.m. 🔄 Last Modified: April 20, 2026, 10 p.m.

4.3

CVSS3.1

CVE-2025-8481 - Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid <= 1.1.7 - Cross-Site Request F…

The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.1.7. This is due to missing or incorrect nonce validation on the bdfe_install_activate_rswpbs_only function. This makes it possible for unauthenticat…

📅 Published: Sept. 11, 2025, 7:24 a.m. 🔄 Last Modified: April 20, 2026, 10 p.m.

4.3

CVSS3.1

CVE-2025-9623 - Admin in English with Switch <= 1.1 - Cross-Site Request Forgery

The Admin in English with Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the enable_eng function. This makes it possible for unauthenticated attackers to modify administrator …

📅 Published: Sept. 11, 2025, 7:24 a.m. 🔄 Last Modified: April 21, 2026, 3 a.m.

6.4

CVSS3.1

CVE-2025-8392 - Mitfahrgelegenheit <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via date Par…

The Mitfahrgelegenheit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access…

📅 Published: Sept. 11, 2025, 7:24 a.m. 🔄 Last Modified: April 22, 2026, 1 a.m.

5.3

CVSS3.1

CVE-2025-8492 - Salon Booking System <= 10.22 - Missing Authorization to Unauthenticated AJAX Actions Execution

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax function in all versions up to, and including, 10.22. This makes it possible for unauthenticated…

📅 Published: Sept. 11, 2025, 7:24 a.m. 🔄 Last Modified: April 21, 2026, 3 a.m.

4.3

CVSS3.1

CVE-2025-9627 - Run Log <= 1.7.10 - Cross-Site Request Forgery to Settings Update

The Run Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.10. This is due to missing or incorrect nonce validation on the oirl_plugin_options function. This makes it possible for unauthenticated attackers to modify plugin settings includi…

📅 Published: Sept. 11, 2025, 7:24 a.m. 🔄 Last Modified: April 21, 2026, 7:15 p.m.

6.4

CVSS3.1

CVE-2025-9860 - Mixtape <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Mixtape plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mixtape' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wi…

📅 Published: Sept. 11, 2025, 7:24 a.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.
Total resulsts: 349182
Page 3905 of 34,919
« previous page » next page
Filters