4.3

CVSS3.1

CVE-2025-4101 - MultiVendorX – WooCommerce Multivendor Marketplace Solutions <= 4.2.22 - Incorrect Authorization to…

The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'delete_fpm_product' function in all versions up to, and including, 4.2.22. This makes it possible for authenticated attack…

📅 Published: May 17, 2025, 12:22 p.m. 🔄 Last Modified: April 21, 2026, 8:45 p.m.

7.5

CVSS3.1

CVE-2024-13613 - Wise Chat <= 3.3.3 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.3 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can…

📅 Published: May 17, 2025, 11:17 a.m. 🔄 Last Modified: April 8, 2026, 5:33 p.m.

6.4

CVSS3.1

CVE-2025-4669 - Booking Calendar <= 10.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Sho…

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at…

📅 Published: May 17, 2025, 11:17 a.m. 🔄 Last Modified: April 21, 2026, 8:45 p.m.

6.4

CVSS3.1

CVE-2025-3888 - Jupiterx Core <= 4.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Inline SVG

The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versions up to, and including, 4.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and …

📅 Published: May 17, 2025, 11:17 a.m. 🔄 Last Modified: April 20, 2026, 11 p.m.

6.4

CVSS3.1

CVE-2025-3527 - EventON - WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated…

The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'assets/lib/settings/settings.js' file in all versions up to, and including, 4.9.6. This makes it possible for authenticated attackers, with Subscriber-level access and a…

📅 Published: May 17, 2025, 11:17 a.m. 🔄 Last Modified: April 22, 2026, 1:45 a.m.

8.7

CVSS4.0

CVE-2025-4826 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWirelessTbl buffer overflow

A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads …

📅 Published: May 17, 2025, 11 a.m. 🔄 Last Modified: May 23, 2025, 3:49 p.m.

8.7

CVSS4.0

CVE-2025-4825 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formDMZ buffer overflow

A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formDMZ of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The atta…

📅 Published: May 17, 2025, 10:07 a.m. 🔄 Last Modified: May 23, 2025, 3:49 p.m.

8.7

CVSS4.0

CVE-2025-4824 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWsc buffer overflow

A vulnerability classified as critical has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible…

📅 Published: May 17, 2025, 10 a.m. 🔄 Last Modified: May 23, 2025, 3:49 p.m.

8.7

CVSS4.0

CVE-2025-4823 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formReflashClientTbl submit-url buffer overflow

A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is the function submit-url of the file /boafrm/formReflashClientTbl of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The …

📅 Published: May 17, 2025, 9:31 a.m. 🔄 Last Modified: May 23, 2025, 3:48 p.m.

6.4

CVSS3.1

CVE-2025-4610 - WP-Members <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_user_membe…

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_user_memberships shortcode in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss…

📅 Published: May 17, 2025, 9:22 a.m. 🔄 Last Modified: April 21, 2026, 8:45 p.m.
Total resulsts: 346671
Page 5107 of 34,668
« previous page » next page
Filters