10

CVSS3.1

CVE-2025-47687 - WordPress StoreKeeper for WooCommerce plugin <= 14.4.4 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects StoreKeeper for WooCommerce: from n/a through <= 14.4.4.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

8.8

CVSS3.1

CVE-2025-47690 - WordPress Lead Form Data Collection to CRM plugin <= 3.1 - Arbitrary Option Update to Privilege Esc…

Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Privilege Escalation.This issue affects Lead Form Data Collection to CRM: from n/a through <= 3.1.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-48241 - WordPress Verge3D plugin <= 4.9.3 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D verge3d allows Reflected XSS.This issue affects Verge3D: from n/a through <= 4.9.3.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-48245 - WordPress Quick Contact Form plugin <= 8.2.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Reflected XSS.This issue affects Quick Contact Form: from n/a through <= 8.2.1.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2025-48271 - WordPress Leadinfo plugin <= 1.1 - Settings Change Vulnerability

Missing Authorization vulnerability in Leadinfo Leadinfo leadinfo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leadinfo: from n/a through <= 1.1.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

7.5

CVSS3.1

CVE-2025-48273 - WordPress WP Job Portal plugin <= 2.3.2 - Arbitrary File Download Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Portal wp-job-portal allows Path Traversal.This issue affects WP Job Portal: from n/a through <= 2.3.2.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

6.5

CVSS3.1

CVE-2025-48275 - WordPress Visual Header plugin <= 1.3 - Broken Access Control Vulnerability

Missing Authorization vulnerability in dastan800 Visual Header visual-header allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visual Header: from n/a through <= 1.3.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

9.3

CVSS3.1

CVE-2025-48283 - WordPress Majestic Support plugin <= 1.1.0 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Majestic Support Majestic Support majestic-support allows SQL Injection.This issue affects Majestic Support: from n/a through <= 1.1.0.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

7.1

CVSS3.1

CVE-2025-48286 - WordPress ReDi Restaurant Reservation plugin <= 24.1209 - Reflected Cross Site Scripting (XSS) vuln…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restaurant Reservation redi-restaurant-reservation allows Reflected XSS.This issue affects ReDi Restaurant Reservation: from n/a through <= 24.1209.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

9.8

CVSS3.1

CVE-2025-48287 - WordPress Pix 4x sem juros - Pagaleve plugin <= 1.6.9 - PHP Object Injection Vulnerability

Deserialization of Untrusted Data vulnerability in Pagaleve Pix 4x sem juros - Pagaleve wc-pagaleve allows Object Injection.This issue affects Pix 4x sem juros - Pagaleve: from n/a through <= 1.6.9.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.
Total resulsts: 347738
Page 5131 of 34,774
Β« previous page Β» next page
Filters