5.3

CVSS3.1

CVE-2025-28995 - WordPress Viral Loops WP Integration plugin <= 3.8.1 - Broken Access Control Vulnerability

Missing Authorization vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Loops WP Integration: from n/a through <= 3.8.1.

๐Ÿ“… Published: June 6, 2025, 12:54 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

4.3

CVSS3.1

CVE-2025-28996 - WordPress GPP Slideshow plugin <= 1.3.5 - Broken Access Control Vulnerability

Missing Authorization vulnerability in Thad Allender GPP Slideshow gpp-slideshow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GPP Slideshow: from n/a through <= 1.3.5.

๐Ÿ“… Published: June 6, 2025, 12:54 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

5.3

CVSS3.1

CVE-2025-28997 - WordPress WP AutoKeyword plugin <= 1.0 - Broken Access Control Vulnerability

Missing Authorization vulnerability in EXEIdeas International WP AutoKeyword wp-autokeyword allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP AutoKeyword: from n/a through <= 1.0.

๐Ÿ“… Published: June 6, 2025, 12:54 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

6.5

CVSS3.1

CVE-2025-29003 - WordPress The Holiday Calendar plugin <= 1.18.2.1 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mva7 The Holiday Calendar the-holiday-calendar allows Stored XSS.This issue affects The Holiday Calendar: from n/a through <= 1.18.2.1.

๐Ÿ“… Published: June 6, 2025, 12:54 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

4.3

CVSS3.1

CVE-2025-29005 - WordPress HR Management Lite plugin <= 3.6 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Weblizar - WordPress Themes & Plugin HR Management Lite hr-management-lite allows Cross Site Request Forgery.This issue affects HR Management Lite: from n/a through <= 3.6.

๐Ÿ“… Published: June 6, 2025, 12:54 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:11 p.m.

5.3

CVSS3.1

CVE-2025-29006 - WordPress Direct Checkout for WooCommerce Lite plugin <= 1.0.3 - Broken Access Control Vulnerability

Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite woo-direct-checkout-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Direct Checkout for WooCommerce Lite: from n/a through <= 1.0.3.

๐Ÿ“… Published: June 6, 2025, 12:54 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

4.9

CVSS3.1

CVE-2025-29008 - WordPress SocialMark plugin <= 2.0.7 - Server Side Request Forgery (SSRF) Vulnerability

Server-Side Request Forgery (SSRF) vulnerability in ShawonPro SocialMark socialmark allows Server Side Request Forgery.This issue affects SocialMark: from n/a through <= 2.0.7.

๐Ÿ“… Published: June 6, 2025, 12:54 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

4.3

CVSS3.1

CVE-2025-29010 - WordPress Behance Portfolio Manager plugin <= 1.7.5 - Broken Access Control vulnerability

Missing Authorization vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Behance Portfolio Manager: from n/a through <= 1.7.5.

๐Ÿ“… Published: June 6, 2025, 12:54 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

6.5

CVSS3.1

CVE-2025-29011 - WordPress YouTube Simple Gallery plugin <= 2.2.0 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CHR Designer YouTube Simple Gallery youtube-simple-gallery allows Stored XSS.This issue affects YouTube Simple Gallery: from n/a through <= 2.2.0.

๐Ÿ“… Published: June 6, 2025, 12:54 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

5.4

CVSS3.1

CVE-2025-29013 - WordPress Custom Category/Post Type Post order plugin <= 1.6.0 - Broken Access Control Vulnerability

Missing Authorization vulnerability in faaiq Custom Category/Post Type Post order custom-post-order-category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Category/Post Type Post order: from n/a through <= 1.6.0.

๐Ÿ“… Published: June 6, 2025, 12:54 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.
Total resulsts: 348450
Page 5065 of 34,845
ยซ previous page ยป next page
Filters