7.1

CVSS3.1

CVE-2025-53305 - WordPress WP Forum Server plugin <= 1.8.2 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in lucidcrew WP Forum Server forum-server allows Stored XSS.This issue affects WP Forum Server: from n/a through <= 1.8.2.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

5.3

CVSS3.1

CVE-2025-53304 - WordPress Contact Form – 7 : Hide Success Message plugin <= 1.1.4 - Broken Access Control Vulnerabi…

Missing Authorization vulnerability in Rohil Contact Form – 7 : Hide Success Message contact-form-7-hide-success-message allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Contact Form – 7 : Hide Success Message: from n/a through <= 1.1.4.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 28, 2026, 4:13 p.m.

6.5

CVSS3.1

CVE-2025-53301 - WordPress Theme Junkie Team Content plugin <= 0.1.1 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Junkie Theme Junkie Team Content theme-junkie-team-content allows DOM-Based XSS.This issue affects Theme Junkie Team Content: from n/a through <= 0.1.1.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

6.5

CVSS3.1

CVE-2025-53300 - WordPress Podcast Feed Player Widget and Shortcode plugin <= 2.2.0 - Cross Site Scripting (XSS) Vul…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in douglaskarr Podcast Feed Player Widget and Shortcode podcast-feed-player-widget allows Stored XSS.This issue affects Podcast Feed Player Widget and Shortcode: from n/a through <= 2.2.0.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

4.9

CVSS3.1

CVE-2025-53298 - WordPress Plugin Inspector plugin <= 1.5 - Arbitrary File Download Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gioni Plugin Inspector plugin-inspector allows Path Traversal.This issue affects Plugin Inspector: from n/a through <= 1.5.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

5.9

CVSS3.1

CVE-2025-53296 - WordPress EC Stars Rating plugin <= 1.0.11 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ecoal95 EC Stars Rating ec-stars-rating allows Stored XSS.This issue affects EC Stars Rating: from n/a through <= 1.0.11.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

5.3

CVSS3.1

CVE-2025-53295 - WordPress iCount Payment Gateway plugin <= 2.0.7 - Broken Access Control Vulnerability

Missing Authorization vulnerability in iCount iCount Payment Gateway icount allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iCount Payment Gateway: from n/a through <= 2.0.7.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

6.5

CVSS3.1

CVE-2025-53294 - WordPress Smart Agenda plugin <= 4.9 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart Agenda smart-agenda-prise-de-rendez-vous-en-ligne allows Stored XSS.This issue affects Smart Agenda: from n/a through <= 4.9.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

4.3

CVSS3.1

CVE-2025-53293 - WordPress Dashboard Widget Sidebar plugin <= 1.2.3 - Broken Access Control Vulnerability

Missing Authorization vulnerability in Morten Dalgaard Johansen Dashboard Widget Sidebar dashboard-widget-sidebar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dashboard Widget Sidebar: from n/a through <= 1.2.3.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

6.5

CVSS3.1

CVE-2025-53292 - WordPress WP DataTable plugin <= 0.2.7 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in samsk WP DataTable wp-datatable allows DOM-Based XSS.This issue affects WP DataTable: from n/a through <= 0.2.7.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.
Total resulsts: 349182
Page 4856 of 34,919
Β« previous page Β» next page
Filters