6.4

CVSS3.1

CVE-2025-6262 - muse.ai video embedding <= 0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via muse-…

The muse.ai video embedding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's muse-ai shortcode in all versions up to, and including, 0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: April 21, 2026, 7:45 p.m.

6.4

CVSS3.1

CVE-2025-6385 - WP Applink <= 0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter

The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and ab…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: April 21, 2026, 7:45 p.m.

4.3

CVSS3.1

CVE-2025-7822 - WP Wallcreeper <= 1.6.1 - Missing Authorization to Authenticated (Susbcriber+) Cache Enable/Disable

The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notices hook in all versions up to, and including, 1.6.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable a…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: April 22, 2026, 4:15 a.m.

9.8

CVSS3.1

CVE-2025-6380 - ONLYOFFICE Docs 1.1.0 - 2.2.0 - Missing Authorization to Unauthenticated Privilege Escalation via c…

The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in versions 1.1.0 to 2.2.0. The plugin’s permission callback only verifies that the supplied, encrypted attachment ID maps to an existing attachment post,…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-8071 - Mine CloudVod <= 2.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via audio Parame…

Mine CloudVod plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘audio’ parameter in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and ab…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: April 22, 2026, 1:15 a.m.

6.4

CVSS3.1

CVE-2025-7966 - Get Youtube Subs <= 3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via subscribe_li…

The Get Youtube Subs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘channel', 'layout', and 'subs_count’ parameters in all versions up to, and including, 3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-6441 - Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | Webina…

The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login token generation due to a missing capability check on the `webinarignition_sign_in_support_staff` and `webinarignition_registe…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: April 21, 2026, 7:45 p.m.

6.5

CVSS3.1

CVE-2025-7780 - AI Engine <= 2.9.4 - Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Re…

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to restrict URL schemes before calling get_audio(). This makes it possible for authenticated attackers, with Subscriber-level acce…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-7640 - hiWeb Export Posts <= 0.9.0.0 - Cross-Site Request Forgery to Arbitrary File Deletion

The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.0.0. This is due to missing or incorrect nonce validation on the tool-dashboard-history.php file. This makes it possible for unauthenticated attackers to delete arbitrar…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: April 21, 2026, 4 a.m.

6.1

CVSS3.1

CVE-2025-5084 - Post Grid Master <= 3.4.13 - Reflected Cross-Site Scripting via argsArray['read_more_text']

The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_text']’ parameter in all versions up to, and including, 3.4.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to …

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: April 22, 2026, 5:15 p.m.
Total resulsts: 349182
Page 4532 of 34,919
« previous page » next page
Filters