7.6

CVSS3.1

CVE-2025-49034 - WordPress Funnel Builder by FunnelKit plugin <= 3.10.2 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder allows SQL Injection.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.10.2.

๐Ÿ“… Published: July 16, 2025, 11:27 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:31 p.m.

6.5

CVSS3.1

CVE-2025-49319 - WordPress Wishlist for WooCommerce <= 3.2.3 - Broken Access Control Vulnerability

Missing Authorization vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wishlist for WooCommerce: from n/a through <= 3.2.3.

๐Ÿ“… Published: July 16, 2025, 11:27 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:31 p.m.

8.5

CVSS3.1

CVE-2025-49876 - WordPress ProfileGrid plugin <= 5.9.5.2 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.5.2.

๐Ÿ“… Published: July 16, 2025, 11:27 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:31 p.m.

6.5

CVSS3.1

CVE-2025-49884 - WordPress Internal Linking of Related Contents plugin <= 1.1.8 - Broken Access Control Vulnerability

Missing Authorization vulnerability in alexvtn Internal Linking of Related Contents internal-linking-of-related-contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Internal Linking of Related Contents: from n/a through <= 1.1.8.

๐Ÿ“… Published: July 16, 2025, 11:27 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:31 p.m.

7.1

CVSS3.1

CVE-2025-49888 - WordPress PW WooCommerce On Sale! plugin <= 1.39 - Broken Access Control Vulnerability

Missing Authorization vulnerability in pimwick PW WooCommerce On Sale! pw-woocommerce-on-sale allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PW WooCommerce On Sale!: from n/a through <= 1.39.

๐Ÿ“… Published: July 16, 2025, 11:27 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:31 p.m.

6.5

CVSS3.1

CVE-2025-50028 - WordPress Ultimate Push Notifications plugin <= 1.2.0 - Broken Access Control Vulnerability

Missing Authorization vulnerability in CodeSolz Ultimate Push Notifications ultimate-push-notifications allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Push Notifications: from n/a through <= 1.2.0.

๐Ÿ“… Published: July 16, 2025, 11:27 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

9.3

CVSS3.1

CVE-2025-52714 - WordPress Traveler theme < 3.2.2 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows SQL Injection.This issue affects Traveler: from n/a through < 3.2.2.

๐Ÿ“… Published: July 16, 2025, 11:27 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.1

CVSS3.1

CVE-2025-52777 - WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmsMinds Pay with Contact Form 7 pay-with-contact-form-7 allows Reflected XSS.This issue affects Pay with Contact Form 7: from n/a through <= 1.0.4.

๐Ÿ“… Published: July 16, 2025, 11:27 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.1

CVSS3.1

CVE-2025-52779 - WordPress Dot html,php,xml etc pages plugin <= 1.0 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot html,php,xml etc pages dot-htmlphpxml-etc-pages allows Reflected XSS.This issue affects Dot html,php,xml etc pages: from n/a through <= 1.0.

๐Ÿ“… Published: July 16, 2025, 11:27 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.1

CVSS3.1

CVE-2025-52786 - WordPress Media Folder plugin <= 1.0.0 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kingdom Creation Media Folder media-folder allows Reflected XSS.This issue affects Media Folder: from n/a through <= 1.0.0.

๐Ÿ“… Published: July 16, 2025, 11:27 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.
Total resulsts: 349182
Page 4621 of 34,919
ยซ previous page ยป next page
Filters