6.4

CVSS3.1

CVE-2025-6039 - ProcessingJS for WordPress <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4wp' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-6782 - GoZen Forms <= 1.1.5 - Unauthenticated SQL Injection via dirGZActiveForm()

The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the dirGZActiveForm() function in all versions up to, and including, 1.1.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. T…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: April 21, 2026, 8 p.m.

4.3

CVSS3.1

CVE-2025-5924 - WP Firebase Push Notification <= 1.2.0 - Cross-Site Request Forgery to Broadcast Notification

The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the wfpn_brodcast_notification_message() function. This makes it possible for unauthenticated attac…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: April 21, 2026, 8 p.m.

7.5

CVSS3.1

CVE-2025-6783 - GoZen Forms <= 1.1.5 - Unauthenticated SQL Injection via emdedSc()

The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() function in all versions up to, and including, 1.1.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This make…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: April 21, 2026, 8 p.m.

6.4

CVSS3.1

CVE-2025-6787 - Smart Docs <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'smartdocs_search' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: April 21, 2026, 8 p.m.

7.5

CVSS3.1

CVE-2025-6814 - Booking X 1.0 - 1.1.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure v…

The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_now() function in versions 1.0 to 1.1.2. This makes it possible for unauthenticated attackers to download all plugin data, including user accounts, user meta, and PayPal c…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-5953 - WP Human Resource Management 2.0.0 - 2.2.17 - Missing Authorization to Authenticated (Employee+) Pr…

The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee() and update_empoyee() functions in versions 2.0.0 through 2.2.17. The AJAX handler reads the client-supplied $_POST['role'] and, after basic cleaning…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: Aug. 13, 2025, 7:29 p.m.

7.2

CVSS3.1

CVE-2025-6586 - Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwap_plugin_locInstall function in all versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: April 20, 2026, 4:30 p.m.

6.4

CVSS3.1

CVE-2025-6729 - PayMaster for WooCommerce <= 0.4.31 - Authenticated (Subscriber+) Server-Side Request Forgery

The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.4.31 via the 'wp_ajax_paym_status' AJAX action This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to …

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: April 22, 2026, 2:45 p.m.

6.5

CVSS3.1

CVE-2025-5956 - WP Human Resource Management 2.0.0 - 2.2.17 - Missing Authorization to Authenticated (Employee+) Ar…

The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authorization within the ajax_delete_employee() function in versions 2.0.0 through 2.2.17. The plugin’s deletion handler reads the client-supplied $_POST['delete'] array and passes each I…

📅 Published: July 4, 2025, 1:44 a.m. 🔄 Last Modified: Aug. 13, 2025, 7:29 p.m.
Total resulsts: 346554
Page 4528 of 34,656
« previous page » next page
Filters