7.3

CVSS3.1

CVE-2025-8105 - Soledad <= 8.6.7 - Unauthenticated Arbitrary Shortcode Execution

The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthentic…

📅 Published: Aug. 16, 2025, 11:11 a.m. 🔄 Last Modified: April 20, 2026, 10:15 p.m.

6.5

CVSS3.1

CVE-2025-8878 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Cont…

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.4. This is due to the software allowing users to execute an ac…

📅 Published: Aug. 16, 2025, 11:11 a.m. 🔄 Last Modified: April 21, 2026, 3:30 a.m.

8.8

CVSS3.1

CVE-2025-8142 - Soledad <= 8.6.7 - Authenticated (Contributor+) Local File Inclusion via 'header_layout'

The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via the 'header_layout' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server…

📅 Published: Aug. 16, 2025, 11:11 a.m. 🔄 Last Modified: April 21, 2026, 3:30 a.m.

1

CVSS4.0

CVE-2025-9092 - Hybrid Module Deployment in Multi-JVM Environments Leading to Resource Exhaustion

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader. This issue affects Bouncy Cast…

📅 Published: Aug. 16, 2025, 10:29 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-8719 - Translate This - Google Translate Web Element Shortcode <= 1.0 - Authenticated (Contributor+) Store…

The Translate This gTranslate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘base_lang’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Cont…

📅 Published: Aug. 16, 2025, 8:27 a.m. 🔄 Last Modified: April 20, 2026, 8 p.m.

5.3

CVSS3.1

CVE-2025-7499 - BetterDocs <= 4.1.1 - Missing Authorization to Private And Password-Protected Posts Information Di…

The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_response function in all versions up t…

📅 Published: Aug. 16, 2025, 7:25 a.m. 🔄 Last Modified: April 22, 2026, 1 a.m.

5.3

CVSS3.1

CVE-2025-8464 - Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.0 - Directory Traversal via `wpcf7_g…

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticated attackers to upload and delete files outside of the origin…

📅 Published: Aug. 16, 2025, 7:25 a.m. 🔄 Last Modified: April 22, 2026, 5:15 p.m.

9.8

CVSS3.1

CVE-2025-8898 - Taxi Booking Manager for Woocommerce | E-cab <= 1.3.0 - Missing Authorization to Unauthenticated Pr…

The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.0. This is due to the plugin not properly validating a user's capabilities prior to updating a plugin setting or their identity …

📅 Published: Aug. 16, 2025, 6:39 a.m. 🔄 Last Modified: April 21, 2026, 3:30 a.m.

5.4

CVSS3.1

CVE-2025-8089 - Advanced iFrame <= 2025.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in version less than, or equal to, 2025.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acces…

📅 Published: Aug. 16, 2025, 6:39 a.m. 🔄 Last Modified: April 21, 2026, 3:30 a.m.

6.4

CVSS3.1

CVE-2025-8896 - User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.…

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization a…

📅 Published: Aug. 16, 2025, 6:39 a.m. 🔄 Last Modified: April 22, 2026, 2:30 p.m.
Total resulsts: 349182
Page 4247 of 34,919
« previous page » next page
Filters