4.3

CVSS3.1

CVE-2025-6062 - Yougler Blogger Profile Page <= v1.01 - Cross-Site Request Forgery to Settings Update

The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due to missing or incorrect nonce validation on the 'yougler-plugin.php' page. This makes it possible for unauthenticated attackers to update the pl…

📅 Published: June 14, 2025, 8:23 a.m. 🔄 Last Modified: June 14, 2025, 9:15 a.m.

6.5

CVSS3.1

CVE-2025-6070 - Restrict File Access <= 1.1.2 - Authenticated (Subscriber+) Arbitrary File Read

The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server…

📅 Published: June 14, 2025, 8:23 a.m. 🔄 Last Modified: June 14, 2025, 9:15 a.m.

4.3

CVSS3.1

CVE-2025-4592 - AI Image Lab – Free AI Image Generator <= 1.0.6 - Cross-Site Request Forgery to API Key Update

The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the 'wpz-ai-images' page. This makes it possible for unauthenticated attackers to update t…

📅 Published: June 14, 2025, 8:23 a.m. 🔄 Last Modified: June 14, 2025, 9:15 a.m.

6.4

CVSS3.1

CVE-2025-5589 - StreamWeasels Kick Integration <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac…

📅 Published: June 14, 2025, 8:23 a.m. 🔄 Last Modified: June 14, 2025, 9:15 a.m.

6.1

CVSS3.1

CVE-2025-6055 - Zen Sticky Social <= 0.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing or incorrect nonce validation on the 'zen-social-sticky/zen-sticky-social.php' page. This makes it possible for unauthenticated attackers to updat…

📅 Published: June 14, 2025, 8:23 a.m. 🔄 Last Modified: June 14, 2025, 9:15 a.m.

8.1

CVSS3.1

CVE-2025-4200 - Zagg - Electronics & Accessories WooCommerce WordPress Theme <= 1.4.1 - Unauthenticated Local File …

The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.1 via the load_view() function that is called via at least three AJAX actions: 'load_more_post', 'load_shop', and 'load_more_product. …

📅 Published: June 14, 2025, 8:23 a.m. 🔄 Last Modified: June 14, 2025, 9:15 a.m.

5.9

CVSS3.1

CVE-2025-4187 - UserPro - Community and User Profile WordPress Plugin <= 5.1.10 - Unauthenticated Arbitrary File Re…

The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 via the userpro_fbconnect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the …

📅 Published: June 14, 2025, 8:23 a.m. 🔄 Last Modified: June 14, 2025, 9:15 a.m.

6.1

CVSS3.1

CVE-2025-6040 - Easy Flashcards <= 0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing or incorrect nonce validation on the 'ef_settings_submenu' page. This makes it possible for unauthenticated attackers to update settings and inject …

📅 Published: June 14, 2025, 8:23 a.m. 🔄 Last Modified: June 14, 2025, 9:15 a.m.

6.4

CVSS3.1

CVE-2025-4216 - DIOT SCADA with MQTT <= 1.0.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and including, 1.0.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

📅 Published: June 14, 2025, 8:23 a.m. 🔄 Last Modified: June 14, 2025, 9:15 a.m.

6.1

CVSS3.1

CVE-2025-6064 - WP URL Shortener <= 1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the 'url_shortener_settings' page. This makes it possible for unauthenticated attackers to update settings and inj…

📅 Published: June 14, 2025, 8:23 a.m. 🔄 Last Modified: June 14, 2025, 9:15 a.m.
Total resulsts: 298007
Page 5 of 29,801
« previous page » next page
Filters