3.1

CVSS3.1

CVE-2025-1400 - Out-of-bounds Read in libplctag library

Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.

📅 Published: May 7, 2025, 7:04 a.m. 🔄 Last Modified: May 7, 2025, 2:13 p.m.

3.1

CVSS3.1

CVE-2025-1399 - Out-of-bounds Read in libplctag library

Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.

📅 Published: May 7, 2025, 7:04 a.m. 🔄 Last Modified: May 7, 2025, 2:13 p.m.

5.4

CVSS3.1

CVE-2025-3766 - Login Lockdown & Protection <= 2.11 - Missing Authorization to Authenticated (Subscriber+) Arbitrar…

The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_tool function in all versions up to, and including, 2.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to …

📅 Published: May 7, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

6.1

CVSS3.1

CVE-2025-4054 - Relevanssi <= 4.24.3 (Free) and <= 2.27.4 (Premium) - Unauthenticated Stored Cross-Site Scripting v…

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 (Free) and <= 2.27.4 (Premium), due to insufficient input sanitization and output escaping. This makes it possible for una…

📅 Published: May 7, 2025, 2:23 a.m. 🔄 Last Modified: April 8, 2026, 6:24 p.m.

6.4

CVSS3.1

CVE-2025-4220 - Xavin's List Subpages <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Xavin&#039;s List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xls' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: May 7, 2025, 1:43 a.m. 🔄 Last Modified: April 8, 2026, 5:28 p.m.

6.4

CVSS3.1

CVE-2025-3860 - CarDealerPress <= 6.8.2505.00 - Authenticated (Contributor+) Stored Cross-Site Scripting via salecl…

The CarDealerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘saleclass' parameter in all versions up to, and including, 6.8.2505.00 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…

📅 Published: May 7, 2025, 1:43 a.m. 🔄 Last Modified: April 8, 2026, 7:24 p.m.

6.4

CVSS3.1

CVE-2025-4055 - Multiple Post Type Order <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via m…

The Multiple Post Type Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mpto' shortcode in all versions up to, and including, 1.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

📅 Published: May 7, 2025, 1:43 a.m. 🔄 Last Modified: April 8, 2026, 5:16 p.m.

8.2

CVSS3.1

CVE-2025-3921 - PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Limited Unauthenticate…

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handel_ajax_req() function in versions 1.9.1 to 7.5.2. This makes it possible for unauthenticated attackers to update arbitrary user's metadata wh…

📅 Published: May 7, 2025, 1:43 a.m. 🔄 Last Modified: May 7, 2025, 2:13 p.m.

8.8

CVSS3.1

CVE-2025-3852 - WPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Authenticated (Subscriber+) Privilege Escalation via Account …

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email & password through the update() function. This makes i…

📅 Published: May 7, 2025, 1:43 a.m. 🔄 Last Modified: July 12, 2025, 4:01 p.m.

8.8

CVSS3.1

CVE-2025-4335 - Woocommerce Multiple Addresses <= 1.0.7.1 - Authenticated (Subscriber+) Privilege Escalation

The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.7.1. This is due to insufficient restrictions on user meta that can be updated through the save_multiple_shipping_addresses() function. This makes it possible for …

📅 Published: May 7, 2025, 1:43 a.m. 🔄 Last Modified: April 8, 2026, 5:10 p.m.
Total resulsts: 343921
Page 5001 of 34,393
« previous page » next page
Filters