4.3

CVSS3.1

CVE-2025-6781 - Copymatic – AI Content Writer & Generator <= 2.1 - Cross-Site Request Forgery to Settings Update

The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the 'copymatic-menu' page. This makes it possible for unauthenticated attackers to update…

📅 Published: July 18, 2025, 4:23 a.m. 🔄 Last Modified: April 20, 2026, 10:15 p.m.

6.1

CVSS3.1

CVE-2025-6053 - Zuppler Online Ordering <= 2.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the 'zuppler-online-ordering-options' page. This makes it possible for unauthenticated attackers to updat…

📅 Published: July 18, 2025, 4:23 a.m. 🔄 Last Modified: April 20, 2026, 10:15 p.m.

6.4

CVSS3.1

CVE-2025-7660 - Map My Locations <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_locations' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic…

📅 Published: July 18, 2025, 4:23 a.m. 🔄 Last Modified: April 21, 2026, 4 a.m.

4.9

CVSS3.1

CVE-2025-7638 - Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.45.0 - Authenticated (Admi…

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to insufficient escaping on the user supplied parameter and lack of sufficient prepara…

📅 Published: July 18, 2025, 4:23 a.m. 🔄 Last Modified: April 21, 2026, 4 a.m.

4.3

CVSS3.1

CVE-2025-5816 - Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship <= 3.2.0 - Insecure Direct Ob…

The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.0 via the get_order_detail() due to missing validation on a user controlled key. This makes it possible for auth…

📅 Published: July 18, 2025, 4:23 a.m. 🔄 Last Modified: April 21, 2026, 7:45 p.m.

8.8

CVSS3.1

CVE-2025-6813 - aapanel WP Toolkit 1.0 - 1.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escal…

The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() function in versions 1.0 to 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass all role checks and ga…

📅 Published: July 18, 2025, 4:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-3740 - School Management System for Wordpress <= 93.1.0 - Authenticated (Subscriber+) Local File Inclusion…

The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary f…

📅 Published: July 18, 2025, 4:23 a.m. 🔄 Last Modified: April 21, 2026, 7:45 p.m.

6.4

CVSS3.1

CVE-2025-7648 - Ruven Themes: Shortcodes <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_button' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe…

📅 Published: July 18, 2025, 4:22 a.m. 🔄 Last Modified: April 22, 2026, 2:45 p.m.

4.4

CVSS3.1

CVE-2025-7431 - Knowledge Base <= 2.3.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Slug

The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level acces…

📅 Published: July 18, 2025, 1:44 a.m. 🔄 Last Modified: April 20, 2026, 8:30 p.m.

5.1

CVSS4.0

CVE-2025-7767 - PHPGurukul Art Gallery Management System edit-art-medium-detail.php cross site scripting

A vulnerability, which was classified as problematic, has been found in PHPGurukul Art Gallery Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/edit-art-medium-detail.php. The manipulation of the argument artmed leads to cross site scripting. The attack…

📅 Published: July 18, 2025, 12:02 a.m. 🔄 Last Modified: July 29, 2025, 8:20 p.m.
Total resulsts: 349182
Page 4600 of 34,919
« previous page » next page
Filters