8.9
CVE-2025-50122 -
AΒ CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generation algorithm is reverse engineered with access to installation or upgrade artifacts.
9.5
CVE-2025-50121 -
AΒ CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a malicious folder is created over the web interface HTTP when enabled. HTTP is disabled by default.
5.9
CVE-2025-6438 -
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection resulting in unauthorized file access when the server is accessed via the network using an application account.
4.1
CVE-2025-6838 - Broken Link Notifier <= 1.3.0 - Authenticated (Contributor+) CSV Injection
The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0 via broken links that are later exported. This makes it possible for authenticated attackers, with Contributor-level access and above, to embed untrusted input into exported CSV β¦
7.2
CVE-2025-6851 - Broken Link Notifier <= 1.3.0 - Unauthenticated Server-Side Request Forgery
The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_blinks() function which ultimately calls the check_url_status_code() function. This makes it possible for unauthenticated attackers to make web requestβ¦
0.0
CVE-2025-53877 -
Not used
0.0
CVE-2025-53878 -
Not used
0.0
CVE-2025-53879 -
Not used
0.0
CVE-2025-53872 -
Not used
0.0
CVE-2025-53873 -
Not used