6.4

CVSS3.1

CVE-2025-6546 - Drive Folder Embedder <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via table…

The Drive Folder Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tablecssclass’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-…

📅 Published: June 26, 2025, 2:22 a.m. 🔄 Last Modified: April 21, 2026, 8:15 p.m.

4.4

CVSS3.1

CVE-2025-5275 - Charitable <= 1.8.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Pri…

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the privacy settings fields in all versions up to, and including, 1.8.6.1 due to insufficient input sanitization and output escaping. Th…

📅 Published: June 26, 2025, 2:22 a.m. 🔄 Last Modified: April 22, 2026, 1:15 a.m.

6.4

CVSS3.1

CVE-2025-6537 - Namasha By Mdesign <= 1.2.00 - Authenticated (Contributor+) Stored Cross-Site Scripting via playico…

The Namasha By Mdesign plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘playicon_title’ parameter in all versions up to, and including, 1.2.00 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l…

📅 Published: June 26, 2025, 2:22 a.m. 🔄 Last Modified: April 22, 2026, 4:15 a.m.

4.3

CVSS3.1

CVE-2025-5932 - Homerunner <= 1.0.30 - Cross-Site Request Forgery to Settings Update

The Homerunner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.30. This is due to missing or incorrect nonce validation on the main_settings() function. This makes it possible for unauthenticated attackers to update plugin settings via a fo…

📅 Published: June 26, 2025, 2:22 a.m. 🔄 Last Modified: April 21, 2026, 8:15 p.m.

6.4

CVSS3.1

CVE-2025-5929 - The Countdown <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via clientId Para…

The The Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘clientId’ parameter in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access …

📅 Published: June 26, 2025, 2:22 a.m. 🔄 Last Modified: April 22, 2026, 4:15 a.m.

6.4

CVSS3.1

CVE-2025-5559 - TimeZoneCalculator <= 3.37 - Authenticated (Contributor+) Stored Cross-Site Scripting

The TimeZoneCalculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'timezonecalculator_output' shortcode in all versions up to, and including, 3.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f…

📅 Published: June 26, 2025, 2:06 a.m. 🔄 Last Modified: April 20, 2026, 10:30 p.m.

6.4

CVSS3.1

CVE-2025-5540 - Event RSVP and Simple Event Management Plugin <= 4.1.0 - Authenticated (Contributor+) Stored Cross-…

The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

📅 Published: June 26, 2025, 2:06 a.m. 🔄 Last Modified: April 21, 2026, 8:15 p.m.

6.4

CVSS3.1

CVE-2025-6258 - WP SoundSystem <= 3.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpsstm-track…

The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a…

📅 Published: June 26, 2025, 2:06 a.m. 🔄 Last Modified: April 22, 2026, 1:30 a.m.

6.4

CVSS3.1

CVE-2025-5564 - GC Social wall <= 1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting

The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' shortcode in all versions up to, and including, 1.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: June 26, 2025, 2:06 a.m. 🔄 Last Modified: April 20, 2026, 10:30 p.m.

9.8

CVSS3.1

CVE-2025-4334 - Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated attackers to register …

📅 Published: June 26, 2025, 2:06 a.m. 🔄 Last Modified: April 22, 2026, 5:15 p.m.
Total resulsts: 349182
Page 4883 of 34,919
« previous page » next page
Filters