8.1
CVE-2025-58215 - WordPress Ziston Theme < 1.4.5 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Ziston ziston allows PHP Local File Inclusion.This issue affects Ziston: from n/a through < 1.4.5.
8.8
CVE-2025-48101 - WordPress Constant Contact for WordPress Plugin <= 4.1.1 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: from n/a through 4.1.1.
7.2
CVE-2025-49430 - WordPress Ultimate Video Player Plugin <= 10.1 - Server Side Request Forgery (SSRF) Vulnerability
Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request Forgery.This issue affects Ultimate Video Player: from n/a through <= 10.1.
5.9
CVE-2025-30875 - WordPress WP Weixin plugin <= 1.3.16 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexandre Froger WP Weixin wp-weixin allows Stored XSS.This issue affects WP Weixin: from n/a through <= 1.3.16.
5.4
CVE-2025-53291 - WordPress Spreadconnect plugin <= 2.1.5 - Broken Access Control Vulnerability
Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a through <= 2.1.5.
5.3
CVE-2025-53340 - WordPress Awesome Support plugin <= 6.3.6 - Sensitive Data Exposure vulnerability
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6.
0.0
CVE-2025-53348 - WordPress Kalium Theme <= 3.18.3 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kalium: from n/a through <= 3.18.3.
8.1
CVE-2025-54709 - WordPress Sala Theme <= 1.1.6 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Sala. This issue affects Sala: from n/a through 1.1.6.
9.8
CVE-2025-32486 - WordPress Material Dashboard plugin <= 1.4.6 - Privilege Escalation Vulnerability
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6.
0.0
CVE-2025-32689 - WordPress Download Manager and Payment Form plugin <= 2.8.2 - Price Manipulation vulnerability
Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects WP SmartPay: from n/a through <= 2.8.2.