8.8

CVSS3.1

CVE-2025-53560 - WordPress Noisa theme <= 2.6.0 - PHP Object Injection Vulnerability

Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa: from n/a through <= 2.6.0.

๐Ÿ“… Published: Aug. 20, 2025, 8:03 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

6.5

CVSS3.1

CVE-2025-53561 - WordPress Prevent files / folders access Plugin <= 2.6.0 - Path Traversal Vulnerability

Path Traversal: '.../...//' vulnerability in miniOrange Prevent files / folders access prevent-file-access allows Path Traversal.This issue affects Prevent files / folders access: from n/a through <= 2.6.0.

๐Ÿ“… Published: Aug. 20, 2025, 8:03 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.1

CVSS3.1

CVE-2025-53562 - WordPress Universal Video Player - Addon for WPBakery Page Builder <= 3.2.1 - Cross Site Scripting โ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg_universal_video_player_addon_visual_composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBโ€ฆ

๐Ÿ“… Published: Aug. 20, 2025, 8:03 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.1

CVSS3.1

CVE-2025-53563 - WordPress Youtube Vimeo Video Player and Slider <= 3.8 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Youtube Vimeo Video Player and Slider video_player_youtube_vimeo allows Reflected XSS.This issue affects Youtube Vimeo Video Player and Slider: from n/a through <= 3.8.

๐Ÿ“… Published: Aug. 20, 2025, 8:03 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.1

CVSS3.1

CVE-2025-53564 - WordPress HTML5 Radio Player - WPBakery Page Builder Addon <= 2.5 - Cross Site Scripting (XSS) Vulnโ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Builder Addon lbg_radio_player_addon_visual_composer allows Reflected XSS.This issue affects HTML5 Radio Player - WPBakery Page Builder Addon: from nโ€ฆ

๐Ÿ“… Published: Aug. 20, 2025, 8:03 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

8.1

CVSS3.1

CVE-2025-53565 - WordPress Widget for Google Reviews <= 1.0.15 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Widget for Google Reviews business-reviews-wp allows PHP Local File Inclusion.This issue affects Widget for Google Reviews: from n/a through <= 1.0.15.

๐Ÿ“… Published: Aug. 20, 2025, 8:03 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

8.1

CVSS3.1

CVE-2025-53567 - WordPress Ghost Kit <= 3.4.1 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK Ghost Kit ghostkit allows PHP Local File Inclusion.This issue affects Ghost Kit: from n/a through <= 3.4.1.

๐Ÿ“… Published: Aug. 20, 2025, 8:03 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

10

CVSS3.1

CVE-2025-53577 - WordPress Global DNS Plugin <= 3.1.0 - Remote Code Execution (RCE) Vulnerability

Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS global-dns allows Remote Code Inclusion.This issue affects Global DNS: from n/a through <= 3.1.0.

๐Ÿ“… Published: Aug. 20, 2025, 8:03 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

9.8

CVSS3.1

CVE-2025-53580 - WordPress Simple Business Directory Pro Plugin < 15.6.9 - Privilege Escalation Vulnerability

Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9.

๐Ÿ“… Published: Aug. 20, 2025, 8:03 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

6.5

CVSS3.1

CVE-2025-53983 - WordPress JetElements For Elementor <= 2.7.7 - Sensitive Data Exposure Vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetElements For Elementor jet-elements allows Retrieve Embedded Sensitive Data.This issue affects JetElements For Elementor: from n/a through <= 2.7.7.

๐Ÿ“… Published: Aug. 20, 2025, 8:03 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 9:51 a.m.
Total resulsts: 349182
Page 4210 of 34,919
ยซ previous page ยป next page
Filters