6.4

CVSS3.1

CVE-2025-5589 - StreamWeasels Kick Integration <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting โ€ฆ

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜status-classic-offline-textโ€™ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacโ€ฆ

๐Ÿ“… Published: June 14, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: June 17, 2025, 6:39 p.m.

6.1

CVSS3.1

CVE-2025-6055 - Zen Sticky Social <= 0.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing or incorrect nonce validation on the 'zen-social-sticky/zen-sticky-social.php' page. This makes it possible for unauthenticated attackers to updatโ€ฆ

๐Ÿ“… Published: June 14, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: June 17, 2025, 6:39 p.m.

8.1

CVSS3.1

CVE-2025-4200 - Zagg - Electronics & Accessories WooCommerce WordPress Theme <= 1.4.1 - Unauthenticated Local File โ€ฆ

The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.1 via the load_view() function that is called via at least three AJAX actions: 'load_more_post', 'load_shop', and 'load_more_product. โ€ฆ

๐Ÿ“… Published: June 14, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: June 17, 2025, 6:39 p.m.

5.9

CVSS3.1

CVE-2025-4187 - UserPro - Community and User Profile WordPress Plugin <= 5.1.10 - Unauthenticated Arbitrary File Reโ€ฆ

The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 via the userpro_fbconnect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the โ€ฆ

๐Ÿ“… Published: June 14, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:42 p.m.

6.1

CVSS3.1

CVE-2025-6040 - Easy Flashcards <= 0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing or incorrect nonce validation on the 'ef_settings_submenu' page. This makes it possible for unauthenticated attackers to update settings and inject โ€ฆ

๐Ÿ“… Published: June 14, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:41 p.m.

6.4

CVSS3.1

CVE-2025-4216 - DIOT SCADA with MQTT <= 1.0.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and including, 1.0.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticatedโ€ฆ

๐Ÿ“… Published: June 14, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:40 p.m.

6.1

CVSS3.1

CVE-2025-6064 - WP URL Shortener <= 1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the 'url_shortener_settings' page. This makes it possible for unauthenticated attackers to update settings and injโ€ฆ

๐Ÿ“… Published: June 14, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:36 p.m.

9.1

CVSS3.1

CVE-2025-6065 - Image Resizer On The Fly <= 1.1 - Unauthenticated Arbitrary File Deletion

The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' task in all versions up to, and including, 1.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which canโ€ฆ

๐Ÿ“… Published: June 14, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:36 p.m.

7.2

CVSS3.1

CVE-2025-5487 - AutomatorWP <= 5.2.5 - Authenticated (Administrator+) SQL Injection via field_conditions

The AutomatorWP โ€“ Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient escaping on the user supplied parโ€ฆ

๐Ÿ“… Published: June 14, 2025, 6:41 a.m. ๐Ÿ”„ Last Modified: June 17, 2025, 6:40 p.m.

7.2

CVSS3.1

CVE-2025-3234 - File Manager Pro โ€“ Filester <= 1.8.8 - Authenticated (Administrator+) Arbitrary File Upload

The File Manager Pro โ€“ Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.8.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on tโ€ฆ

๐Ÿ“… Published: June 14, 2025, 5:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:32 p.m.
Total resulsts: 343194
Page 4431 of 34,320
ยซ previous page ยป next page
Filters