9.8

CVSS3.1

CVE-2025-54713 - WordPress Taxi Booking Manager for WooCommerce plugin <= 1.3.0 - Broken Authentication vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Authentication Abuse.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.3.0.

πŸ“… Published: Aug. 20, 2025, 8:02 a.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

9.3

CVSS3.1

CVE-2025-54726 - WordPress JS Archive List Plugin < 6.1.6 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows SQL Injection.This issue affects JS Archive List: from n/a through < 6.1.6.

πŸ“… Published: Aug. 20, 2025, 8:02 a.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

8.8

CVSS3.1

CVE-2025-54735 - WordPress CubeWP Framework Plugin <= 1.1.24 - Privilege Escalation Vulnerability

Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This issue affects CubeWP: from n/a through <= 1.1.24.

πŸ“… Published: Aug. 20, 2025, 8:02 a.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.5

CVSS3.1

CVE-2025-54750 - WordPress Funnel Builder by FunnelKit Plugin <= 3.11.1 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder allows PHP Local File Inclusion.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.11.1.

πŸ“… Published: Aug. 20, 2025, 8:02 a.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.5

CVSS3.1

CVE-2025-55715 - WordPress Otter - Gutenberg Block Plugin <= 3.1.0 - Sensitive Data Exposure Vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Retrieve Embedded Sensitive Data.This issue affects Otter - Gutenberg Block: from n/a through <= 3.1.0.

πŸ“… Published: Aug. 20, 2025, 8:02 a.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

5.5

CVSS3.1

CVE-2025-9225 - Cross-site scripting (XSS) in MiR robots and MiR fleet

Stored cross-site scripting (XSS) in the web interface of MiR software versions prior to 3.0.0 on MiR Robots and MiR Fleet allows execution of arbitrary JavaScript code in a victim’s browser

πŸ“… Published: Aug. 20, 2025, 7:26 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-9202 - ColorMag <= 4.0.19 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer …

The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and ab…

πŸ“… Published: Aug. 20, 2025, 6:39 a.m. πŸ”„ Last Modified: April 20, 2026, 10 p.m.

5.3

CVSS4.0

CVE-2025-54551 -

Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the product may escalate the privilege and access data that the user do not have permission to view by altering the parameters of the se…

πŸ“… Published: Aug. 20, 2025, 4:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-8618 - WPC Smart Quick View for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scri…

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible …

πŸ“… Published: Aug. 20, 2025, 4:26 a.m. πŸ”„ Last Modified: April 22, 2026, 1 a.m.

5.1

CVSS4.0

CVE-2025-55706 -

URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the password reset page, which may lead to redirection to an arbitrary URL.

πŸ“… Published: Aug. 20, 2025, 4:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4214 of 34,919
Β« previous page Β» next page
Filters