7.5

CVSS3.1

CVE-2025-6437 - Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated SQL Injectio…

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘oid’ parameter in all versions up to, and including, 4.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL …

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 4:55 p.m.

7.2

CVSS3.1

CVE-2025-5817 - Amazon Products to WooCommerce <= 1.2.7 - Unauthenticated Server-Side Request Forgery

The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.7 via the wcta2w_get_urls(). This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web appli…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 4:52 p.m.

3.7

CVSS3.1

CVE-2025-4654 - Soumettre.fr <= 2.1.5 - Improper Authorization to Unauthenticated Soumettre Posts Creation/Modifica…

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper authorization checks on the make_signature function in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to create/edit/delete Soumettre…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 4:51 p.m.

6.4

CVSS3.1

CVE-2025-6686 - Magic Buttons for Elementor <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via m…

The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on the 'text' user supplied attribute. This makes it possibl…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 6:25 p.m.

9.8

CVSS3.1

CVE-2025-5746 - Drag and Drop Multiple File Upload (Pro) - WooCommerce <= 1.7.1 and 5.0 - 5.0.5 - Unauthenticated A…

The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dnd_upload_cf7_upload_chunks() function in version 5.0 - 5.0.5 (when bundled with the PrintSpace theme) and all versions up to, and incl…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 6:24 p.m.

8.1

CVSS3.1

CVE-2025-4380 - Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File I…

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa_template' parameter of the `bsa_preview_callback` function. This makes it possible for unauthenticated attackers to inc…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 4:44 p.m.

6.4

CVSS3.1

CVE-2025-6687 - Magic Buttons for Elementor <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via m…

The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on the 'icon' user supplied attributes. This makes it possib…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

8.8

CVSS3.1

CVE-2025-6459 - Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Cross-Site Request Forgery t…

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.89. This is due to missing or incorrect nonce validation on the bsaCreateAdTemplate function. This makes it possible for unauthen…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

7.5

CVSS3.1

CVE-2025-4381 - Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated SQL Injection

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘$id’ variable of the getSpace() function in all versions up to, and including, 4.89 due to insufficient escaping on the user supplied parameter and lack of sufficient prepar…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.

9.8

CVSS3.1

CVE-2025-4689 - Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File I…

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Code Execution in all versions up to, and including, 4.89. This is due to the presence of a SQL Injection vulnerability and Local File Inclusion vulnerab…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 4:32 p.m.
Total resulsts: 344059
Page 4309 of 34,406
« previous page » next page
Filters