6.4

CVSS3.1

CVE-2025-7843 - Auto Save Remote Images (Drafts) <= 1.0.9 - Authenticated (Contributor+) Server-Side Request Forgery

The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 via the fetch_images() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to ar…

📅 Published: Sept. 10, 2025, 6:38 a.m. 🔄 Last Modified: April 21, 2026, 7:15 p.m.

6.5

CVSS3.1

CVE-2025-7826 - Testimonial <= 2.3 - Authenticated (Contributor+) SQL Injection

The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions up to, and including, 2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for auth…

📅 Published: Sept. 10, 2025, 6:38 a.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.

5.5

CVSS3.1

CVE-2025-9367 - Welcart e-Commerce <= 2.11.20 - Authenticated (Editor+) Stored Cross-Site Scripting

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above…

📅 Published: Sept. 10, 2025, 6:38 a.m. 🔄 Last Modified: April 21, 2026, 7:15 p.m.

4.3

CVSS3.1

CVE-2025-9979 - Maspik <= 2.5.6 - Authenticated (Subscriber+) Missing Authorization to Spam Log Export

The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download…

📅 Published: Sept. 10, 2025, 6:38 a.m. 🔄 Last Modified: April 21, 2026, 7:15 p.m.

4.3

CVSS3.1

CVE-2025-8778 - NitroPack <= 1.18.4 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update …

The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in all versions up to, and including, 1.18.4. This makes it possible for authenticated attackers, with Subscriber-level access and…

📅 Published: Sept. 10, 2025, 6:38 a.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.

6.5

CVSS3.1

CVE-2025-9463 - Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net <= 1.117…

The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 1.117.5 due to insufficient escaping on the user supplied parameter and la…

📅 Published: Sept. 10, 2025, 6:38 a.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.

6.5

CVSS3.1

CVE-2025-6189 - Duplicate Page and Post <= 2.9.5 - Authenticated (Contributor+) SQL Injection via meta_key Parameter

The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter in all versions up to, and including, 2.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i…

📅 Published: Sept. 10, 2025, 6:38 a.m. 🔄 Last Modified: April 22, 2026, 1 a.m.

8.8

CVSS3.1

CVE-2025-7049 - WPGYM - Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Privilege Escalatio…

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ_gmgt_gmgt_add_user' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with S…

📅 Published: Sept. 10, 2025, 6:38 a.m. 🔄 Last Modified: April 22, 2026, 2:30 p.m.

7.2

CVSS3.1

CVE-2025-10049 - Responsive Filterable Portfolio <= 1.0.24 - Authenticated (Admin+) Arbitrary File Upload

The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the HdnMediaSelection_image field in all versions up to, and including, 1.0.24. This makes it possible for authenticated attackers, with Administrator-level acces…

📅 Published: Sept. 10, 2025, 6:38 a.m. 🔄 Last Modified: April 22, 2026, 10:30 p.m.

6.4

CVSS3.1

CVE-2025-8388 - PowerPack Lite for Elementor <= 2.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting Vi…

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_url’ parameter in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for…

📅 Published: Sept. 10, 2025, 4:22 a.m. 🔄 Last Modified: April 22, 2026, 2:30 p.m.
Total resulsts: 349182
Page 3921 of 34,919
« previous page » next page
Filters