4.4

CVSS3.1

CVE-2025-6719 - Terms descriptions <= 3.4.8 - Authenticated (Admin+) Stored Cross-Site Scripting

The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permission…

📅 Published: July 18, 2025, 5:23 a.m. 🔄 Last Modified: April 20, 2026, 10:15 p.m.

4.3

CVSS3.1

CVE-2025-6726 - Block Editor Gallery Slider <= 1.1.1 - Missing Authorization to Authenticated (Subscriber+) Limited…

The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the classic_gallery_slider_options() function in all versions up to, and including, 1.1.1. This makes it possible for authenticated attackers, with Subscriber…

📅 Published: July 18, 2025, 5:23 a.m. 🔄 Last Modified: April 21, 2026, 4 a.m.

9.1

CVSS3.1

CVE-2025-7643 - Attachment Manager <= 2.1.2 - Unauthenticated Arbitrary File Deletion

The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handle_actions() function in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, w…

📅 Published: July 18, 2025, 5:23 a.m. 🔄 Last Modified: April 22, 2026, 1:15 a.m.

6.4

CVSS3.1

CVE-2025-5754 - Useful Tab Block – Responsive & AMP-Compatible <= 1.3.2 - Authenticated (Contributor+) Stored Cross…

The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke…

📅 Published: July 18, 2025, 5:23 a.m. 🔄 Last Modified: April 21, 2026, 7:45 p.m.

8.8

CVSS3.1

CVE-2025-6718 - B1.lt for WooCommerce <= 2.2.57 - Missing Authorization to Authenticated (Subscriber+) Arbitrary S…

The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX action in all versions up to, and including, 2.2.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute and run arbitrary SQL …

📅 Published: July 18, 2025, 5:23 a.m. 🔄 Last Modified: April 21, 2026, 4 a.m.

9.8

CVSS3.1

CVE-2025-6222 - WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet <…

The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ced_rnx_order_exchange_attach_files' function in all versions up to, and including, 3.2.6. Th…

📅 Published: July 18, 2025, 5:23 a.m. 🔄 Last Modified: April 21, 2026, 7:45 p.m.

4.3

CVSS3.1

CVE-2025-6781 - Copymatic – AI Content Writer & Generator <= 2.1 - Cross-Site Request Forgery to Settings Update

The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the 'copymatic-menu' page. This makes it possible for unauthenticated attackers to update…

📅 Published: July 18, 2025, 4:23 a.m. 🔄 Last Modified: April 20, 2026, 10:15 p.m.

6.1

CVSS3.1

CVE-2025-6053 - Zuppler Online Ordering <= 2.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the 'zuppler-online-ordering-options' page. This makes it possible for unauthenticated attackers to updat…

📅 Published: July 18, 2025, 4:23 a.m. 🔄 Last Modified: April 20, 2026, 10:15 p.m.

6.4

CVSS3.1

CVE-2025-7660 - Map My Locations <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_locations' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic…

📅 Published: July 18, 2025, 4:23 a.m. 🔄 Last Modified: April 21, 2026, 4 a.m.

4.9

CVSS3.1

CVE-2025-7638 - Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.45.0 - Authenticated (Admi…

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to insufficient escaping on the user supplied parameter and lack of sufficient prepara…

📅 Published: July 18, 2025, 4:23 a.m. 🔄 Last Modified: April 21, 2026, 4 a.m.
Total resulsts: 348208
Page 4502 of 34,821
« previous page » next page
Filters