4.3

CVSS3.1

CVE-2025-58794 - WordPress Notification for Telegram plugin <= 3.5 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in rainafarai Notification for Telegram notification-for-telegram allows Cross Site Request Forgery.This issue affects Notification for Telegram: from n/a through <= 3.5.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 28, 2026, 4:13 p.m.

6.5

CVSS3.1

CVE-2025-58793 - WordPress WPB Elementor Addons plugin <= 1.7 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBean WPB Elementor Addons wpb-elementor-addons allows Stored XSS.This issue affects WPB Elementor Addons: from n/a through <= 1.7.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

4.3

CVSS3.1

CVE-2025-58792 - WordPress Authors List plugin <= 2.0.6.2 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List authors-list allows Cross Site Request Forgery.This issue affects Authors List: from n/a through <= 2.0.6.2.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.9

CVSS3.1

CVE-2025-58791 - WordPress SEO Auto Linker Plugin <= 1.5.3 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arjan Olsder SEO Auto Linker wpa-seo-auto-linker allows Stored XSS.This issue affects SEO Auto Linker: from n/a through <= 1.5.3.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-58790 - WordPress Kiwi Plugin <= 2.1.8 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Kiwi kiwi-social-share allows Stored XSS.This issue affects Kiwi: from n/a through <= 2.1.8.

πŸ“… Published: Sept. 5, 2025, 1:44 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

7.6

CVSS3.1

CVE-2025-58789 - WordPress WP Full Stripe Free Plugin <= 8.2.5 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free wp-full-stripe-free allows SQL Injection.This issue affects WP Full Stripe Free: from n/a through <= 8.2.5.

πŸ“… Published: Sept. 5, 2025, 1:44 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

7.6

CVSS3.1

CVE-2025-58788 - WordPress License Manager for WooCommerce Plugin <= 3.0.12 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.12.

πŸ“… Published: Sept. 5, 2025, 1:44 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-58787 - WordPress Themify Popup Plugin <= 1.4.2 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Popup themify-popup allows Stored XSS.This issue affects Themify Popup: from n/a through <= 1.4.2.

πŸ“… Published: Sept. 5, 2025, 1:44 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-58786 - WordPress Ibtana – Ecommerce Product Addons plugin <= 0.4.7.6 - Cross Site Scripting (XSS) vulnerab…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana – Ecommerce Product Addons ibtana-ecommerce-product-addons allows DOM-Based XSS.This issue affects Ibtana – Ecommerce Product Addons: from n/a through <= 0.4.7.6.

πŸ“… Published: Sept. 5, 2025, 1:44 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.4

CVSS3.1

CVE-2025-58785 - WordPress Ray Enterprise Translation plugin <= 1.7.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ray Enterprise Translation: from n/a through <= 1.7.2.

πŸ“… Published: Sept. 5, 2025, 1:44 p.m. πŸ”„ Last Modified: April 28, 2026, 4:13 p.m.
Total resulsts: 349182
Page 3990 of 34,919
Β« previous page Β» next page
Filters