6.4

CVSS3.1

CVE-2025-9853 - Optio Dentistry <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' shortcode in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticateโ€ฆ

๐Ÿ“… Published: Sept. 6, 2025, 2:24 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 10 p.m.

9.8

CVSS3.1

CVE-2025-8359 - AdForest <= 6.0.9 - Authentication Bypass to Admin

The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, includโ€ฆ

๐Ÿ“… Published: Sept. 6, 2025, 2:24 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 10 p.m.

4.9

CVSS3.1

CVE-2025-9085 - User Registration & Membership <= 4.3.0 - Authenticated (Admin+) SQL Injection

The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated aโ€ฆ

๐Ÿ“… Published: Sept. 6, 2025, 2:24 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:45 p.m.

7.2

CVSS3.1

CVE-2025-9515 - Multi Step Form <= 1.7.25 - Authenticated (Admin+) Arbitrary File Upload

The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the import functionality in all versions up to, and including, 1.7.25. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arโ€ฆ

๐Ÿ“… Published: Sept. 6, 2025, 2:24 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:45 p.m.

6.4

CVSS3.1

CVE-2025-8360 - LA-Studio Element Kit for Elementor <= 1.5.5.1 - Authenticated (Contributor+) Stored Cross-Site Scrโ€ฆ

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets in all versions up to, and including, 1.5.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible โ€ฆ

๐Ÿ“… Published: Sept. 6, 2025, 2:24 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 7:30 a.m.

7.8

CVSS3.1

CVE-2025-58374 - Roo Code: Auto-approve allows npm install execution of malicious postinstall scripts

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that do not need manual approval if auto-approve is enabled, and npm install is included in that list. Because npm install executes lifecycle scriptsโ€ฆ

๐Ÿ“… Published: Sept. 6, 2025, 2:19 a.m. ๐Ÿ”„ Last Modified: Sept. 15, 2025, 6:07 p.m.

6.4

CVSS3.1

CVE-2025-6067 - Easy Social Feed โ€“ Social Photos Gallery โ€“ Post Feed โ€“ Like Box <= 6.6.7 - Authenticated (Contributโ€ฆ

The Easy Social Feed โ€“ Social Photos Gallery โ€“ Post Feed โ€“ Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` and `data-linktext` parameters in all versions up to, and including, 6.6.7 due to insufficient input sanitization and output escaping. This maโ€ฆ

๐Ÿ“… Published: Sept. 6, 2025, 1:47 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 7:15 p.m.

6.4

CVSS3.1

CVE-2025-9849 - Html Social share buttons <= 2.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zm_sh_btn' shortcode in all versions up to, and including, 2.1.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authโ€ฆ

๐Ÿ“… Published: Sept. 6, 2025, 1:45 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:45 p.m.

5.3

CVSS3.1

CVE-2025-7368 - Rehub <= 19.9.7 - Unauthenticated Password Protected Post Disclosure

The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 19.9.7 via the 'ajax_action_re_getfullcontent' function due to insufficient restrictions on which posts can be included. This makes โ€ฆ

๐Ÿ“… Published: Sept. 6, 2025, 1:45 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 3:30 a.m.

7.3

CVSS3.1

CVE-2025-7366 - Rehub <= 19.9.7 - Unauthenticated Arbitrary Shortcode Execution via re_filterpost

The The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 19.9.7. This is due to the software allowing users to execute an action that does not properly validate a value before โ€ฆ

๐Ÿ“… Published: Sept. 6, 2025, 1:45 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 7:15 p.m.
Total resulsts: 349182
Page 3975 of 34,919
ยซ previous page ยป next page
Filters