8.1

CVSS3.1

CVE-2025-58214 - WordPress Indutri Theme < 1.3.0 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Indutri indutri allows PHP Local File Inclusion.This issue affects Indutri: from n/a through < 1.3.0.

πŸ“… Published: Sept. 5, 2025, 4:18 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

9.3

CVSS3.1

CVE-2025-58628 - WordPress Miraculous Theme < 2.0.9 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous miraculous allows Blind SQL Injection.This issue affects Miraculous: from n/a through < 2.0.9.

πŸ“… Published: Sept. 5, 2025, 4:17 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.9

CVSS3.1

CVE-2025-48102 - WordPress GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership plugin <= 1.6.6 - Cross Site …

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gourl GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership gourl-bitcoin-payment-gateway-paid-downloads-membership allows Stored XSS.This issue affects GoUrl Bitcoin Payment Gateway & Paid D…

πŸ“… Published: Sept. 5, 2025, 4:15 p.m. πŸ”„ Last Modified: April 28, 2026, 4:12 p.m.

6.5

CVSS3.1

CVE-2025-48103 - WordPress Today's Date Inserter plugin <= 1.2.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mulscully Today's Date Inserter todays-date-inserter allows Stored XSS.This issue affects Today's Date Inserter: from n/a through <= 1.2.1.

πŸ“… Published: Sept. 5, 2025, 4:15 p.m. πŸ”„ Last Modified: April 28, 2026, 4:12 p.m.

7.1

CVSS3.1

CVE-2025-48104 - WordPress Floating Window Music Player plugin <= 3.4.2 - Cross Site Request Forgery (CSRF) to Store…

Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player allows Stored XSS.This issue affects Floating Window Music Player: from n/a through <= 3.4.2.

πŸ“… Published: Sept. 5, 2025, 4:15 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2025-48105 - WordPress Easy Flash Embed plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Boiardt Easy Flash Embed easy-flash-embed allows Stored XSS.This issue affects Easy Flash Embed: from n/a through <= 1.0.

πŸ“… Published: Sept. 5, 2025, 4:15 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.5

CVSS3.1

CVE-2025-48317 - WordPress WooCommerce Payment Gateway for Saferpay Plugin <= 0.4.9 - Path Traversal Vulnerability

Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-gateway-for-saferpay allows Path Traversal.This issue affects WooCommerce Payment Gateway for Saferpay: from n/a through <= 0.4.9.

πŸ“… Published: Sept. 5, 2025, 4:15 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

9.8

CVSS3.1

CVE-2025-49401 - WordPress smart SEO Plugin <= 4.0 - Privilege Escalation Vulnerability

Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue affects smart SEO: from n/a through <= 4.0.

πŸ“… Published: Sept. 5, 2025, 4:15 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

7.1

CVSS3.1

CVE-2025-53307 - WordPress Assistant Plugin <= 1.5.2 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from n/a through <= 1.5.2.

πŸ“… Published: Sept. 5, 2025, 4:15 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

6.5

CVSS3.1

CVE-2025-54744 - WordPress MasterStudy LMS plugin <= 3.6.15 - Broken Access Control vulnerability

Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from n/a through <= 3.6.15.

πŸ“… Published: Sept. 5, 2025, 4:15 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.
Total resulsts: 349182
Page 3979 of 34,919
Β« previous page Β» next page
Filters