6.4

CVSS3.1

CVE-2025-8149 - aThemes Addons for Elementor Lite <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Sept. 6, 2025, 3:22 a.m. 🔄 Last Modified: April 20, 2026, 7:45 p.m.

6.4

CVSS3.1

CVE-2025-8564 - SKT Addons for Elementor <= 3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Mult…

The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w…

📅 Published: Sept. 6, 2025, 3:22 a.m. 🔄 Last Modified: April 21, 2026, 7:15 p.m.

6.5

CVSS3.1

CVE-2025-7045 - Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Identity Provider Deletion via …

The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. This makes it possible for unauthenticated attackers to delete any co…

📅 Published: Sept. 6, 2025, 3:22 a.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.

6.4

CVSS3.1

CVE-2025-9493 - Admin Menu Editor <= 1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via placeholde…

The Admin Menu Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access…

📅 Published: Sept. 6, 2025, 3:22 a.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.

8.2

CVSS3.1

CVE-2025-7040 - Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Settings Modification via set_o…

The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization_settings' action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. The handler reads client-supplied POST parameter…

📅 Published: Sept. 6, 2025, 3:22 a.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.

6.4

CVSS3.1

CVE-2025-9442 - StreamWeasels Kick Integration <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChannel’ parameter in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contr…

📅 Published: Sept. 6, 2025, 3:22 a.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.

6.4

CVSS3.1

CVE-2025-9126 - Smart Table Builder <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Para…

The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access …

📅 Published: Sept. 6, 2025, 3:22 a.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.

6.4

CVSS3.1

CVE-2025-8722 - Content Views <= 4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Grid and List W…

The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid and List widgets in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac…

📅 Published: Sept. 6, 2025, 3:22 a.m. 🔄 Last Modified: April 22, 2026, 2:30 p.m.

8.1

CVSS3.1

CVE-2025-58437 - Coder's privilege escalation vulnerability could lead to a cross workspace compromise

Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automatically generates a session token for a user when a workspace …

📅 Published: Sept. 6, 2025, 2:30 a.m. 🔄 Last Modified: Oct. 17, 2025, 1:54 p.m.

6.5

CVSS3.1

CVE-2025-10003 - UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP <…

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘upload_file_remove’ function and 'htmlvar' parameter in all versions up to, and including, 1.2.44 due to insufficient …

📅 Published: Sept. 6, 2025, 2:24 a.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.
Total resulsts: 349182
Page 3974 of 34,919
« previous page » next page
Filters