7.2
CVE-2025-52718 - WordPress Alone theme <= 7.8.2 - Arbitrary Code Execution Vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Remote Code Inclusion.This issue affects Alone: from n/a through <= 7.8.2.
7.1
CVE-2025-52776 - WordPress Video List Manager plugin <= 1.7 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thanhtungtnt Video List Manager video-list-manager allows Stored XSS.This issue affects Video List Manager: from n/a through <= 1.7.
7.1
CVE-2025-52796 - WordPress WP-Recall plugin <= 16.26.14 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tggfref WP-Recall wp-recall allows Reflected XSS.This issue affects WP-Recall: from n/a through <= 16.26.14.
7.1
CVE-2025-52798 - WordPress JobSearch plugin < 3.0.6 - Reflected Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Reflected XSS.This issue affects JobSearch: from n/a through < 3.0.6.
7.5
CVE-2025-52805 - WordPress Leyka plugin <= 3.32.1 - Local File Inclusion vulnerability
Path Traversal: '.../...//' vulnerability in VaultDweller Leyka leyka allows PHP Local File Inclusion.This issue affects Leyka: from n/a through <= 3.32.1.
8.1
CVE-2025-52807 - WordPress Kossy - Minimalist eCommerce WordPress Theme <= 1.45 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Kossy - Minimalist eCommerce WordPress Theme kossy allows PHP Local File Inclusion.This issue affects Kossy - Minimalist eCommerce WordPress Theme: from n/a through <= 1.4โฆ
8.1
CVE-2025-52813 - WordPress MobiLoud plugin <= 4.6.6 - Broken Access Control Vulnerability
Missing Authorization vulnerability in pietro MobiLoud mobiloud-mobile-app-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MobiLoud: from n/a through <= 4.6.6.
8.8
CVE-2025-52828 - WordPress Red Art theme <= 3.8 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in designthemes Red Art redart allows Object Injection.This issue affects Red Art: from n/a through <= 3.8.
9.3
CVE-2025-52830 - WordPress bSecure โ Your Universal Checkout plugin <= 1.7.9 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSecure - Your Universal Checkout bSecure – Your Universal Checkout bsecure allows Blind SQL Injection.This issue affects bSecure – Your Universal Checkout: from n/a through <= 1.7.9.
9.3
CVE-2025-52831 - WordPress Video List Manager plugin <= 1.7 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video List Manager video-list-manager allows SQL Injection.This issue affects Video List Manager: from n/a through <= 1.7.