7.1

CVSS3.1

CVE-2025-48159 - WordPress Youtube Vimeo Video Player and Slider WP Plugin <= 3.8 - Cross Site Scripting (XSS) Vulne…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Youtube Vimeo Video Player and Slider WP Plugin video-player-youtube-vimeo allows Reflected XSS.This issue affects Youtube Vimeo Video Player and Slider WP Plugin: from n/a through <= …

πŸ“… Published: Aug. 20, 2025, 8:03 a.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

8.1

CVSS3.1

CVE-2025-48160 - WordPress Caliris <= 1.5 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Caliris caliris-wp allows PHP Local File Inclusion.This issue affects Caliris: from n/a through <= 1.5.

πŸ“… Published: Aug. 20, 2025, 8:03 a.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-48162 - WordPress Simple Business Directory Pro <= 15.5.1 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Reflected XSS.This issue affects Simple Business Directory Pro: from n/a through <= 15.5.1.

πŸ“… Published: Aug. 20, 2025, 8:03 a.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-48163 - WordPress SHOUT - HTML5 Radio Player With Ads - ShoutCast and IceCast Support <= 3.5.4 - Cross Site…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup SHOUT - HTML5 Radio Player With Ads - ShoutCast and IceCast Support lbg-audio8-html5-radio-ads allows Reflected XSS.This issue affects SHOUT - HTML5 Radio Player With Ads - ShoutCast a…

πŸ“… Published: Aug. 20, 2025, 8:03 a.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

8.8

CVSS3.1

CVE-2025-48164 - WordPress SureDash <= 1.0.3 - Privilege Escalation Vulnerability

Incorrect Privilege Assignment vulnerability in Brainstorm Force SureDash suredash allows Privilege Escalation.This issue affects SureDash: from n/a through <= 1.0.3.

πŸ“… Published: Aug. 20, 2025, 8:03 a.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

8.8

CVSS3.1

CVE-2025-48165 - WordPress DELUCKS SEO Plugin <= 2.6.0 - Privilege Escalation Vulnerability

Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Privilege Escalation.This issue affects DELUCKS SEO: from n/a through <= 2.6.0.

πŸ“… Published: Aug. 20, 2025, 8:03 a.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-48168 - WordPress Apollo - Sticky Full Width HTML5 Audio Player <= 3.4 - Cross Site Scripting (XSS) Vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Apollo - Sticky Full Width HTML5 Audio Player lbg-audio5-html5-shoutcast-sticky allows Reflected XSS.This issue affects Apollo - Sticky Full Width HTML5 Audio Player: from n/a through …

πŸ“… Published: Aug. 20, 2025, 8:03 a.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

9.9

CVSS3.1

CVE-2025-48169 - WordPress Code Engine Plugin <= 0.3.3 - Remote Code Execution (RCE) Vulnerability

Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Remote Code Inclusion.This issue affects Code Engine: from n/a through <= 0.3.3.

πŸ“… Published: Aug. 20, 2025, 8:03 a.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-48170 - WordPress Universal Video Player - Addon for WPBakery Page Builder <= 3.2.1 - Cross Site Scripting …

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg-universal-video-player-addon-visual-composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPB…

πŸ“… Published: Aug. 20, 2025, 8:03 a.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

8.1

CVSS3.1

CVE-2025-48171 - WordPress Cena Store <= 2.11.26 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Cena Store cena allows PHP Local File Inclusion.This issue affects Cena Store: from n/a through <= 2.11.26.

πŸ“… Published: Aug. 20, 2025, 8:03 a.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.
Total resulsts: 349182
Page 4207 of 34,919
Β« previous page Β» next page
Filters