9.8

CVSS3.1

CVE-2025-5486 - WP Email Debug 1.0 - 1.1.0 - Missing Authorization to Unauthenticated Privilege Escalation via Pass…

The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 to 1.1.0. This makes it possible for unauthenticated attackers to enable debugging and send all emails to an attacker controlled …

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-5541 - Runners Log <= 3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Runners Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'runnerslog' shortcode in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 20, 2026, 10:45 p.m.

6.4

CVSS3.1

CVE-2025-5565 - Hide It <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Hide It plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hideit' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 21, 2026, 8:30 p.m.

5.4

CVSS3.1

CVE-2025-2935 - Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms <= 2024.7 - Cross-Site Request Forge…

The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.7. This is due to missing or incorrect nonce validation in the 'ss_option_maint.php' and 'ss_user_filter_list' files. This m…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 20, 2026, 10:45 p.m.

6.4

CVSS3.1

CVE-2025-5538 - BNS Featured Category <= 2.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The BNS Featured Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bnsfc' shortcode in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 20, 2026, 10:45 p.m.

4.9

CVSS3.1

CVE-2025-4964 - WP Online Users Stats <= 1.0.0 - Authenticated (Editor+) SQL Injection via table_name Parameter

The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 20, 2026, 10:45 p.m.

6.1

CVSS3.1

CVE-2025-4966 - WP Online Users Stats <= 1.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via hk_d…

The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation within the hk_dataset_results() function. This makes it possible for unauthenticated attackers to inject malicious web scri…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 20, 2026, 10:45 p.m.

7.1

CVSS3.1

CVE-2025-5018 - Hive Support <= 1.2.5 - Authenticated (Subscriber+) Missing Authorization via hs_update_ai_chat_set…

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.5. This makes it possible for authenti…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 21, 2026, 8:30 p.m.

6.4

CVSS3.1

CVE-2025-5536 - Freemind Viewer <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Freemind Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'freemind' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 21, 2026, 8:30 p.m.

6.4

CVSS3.1

CVE-2025-5703 - StageShow <= 10.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via anchor Parameter

The StageShow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘anchor’ parameter in all versions up to, and including, 10.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and a…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 21, 2026, 8:30 p.m.
Total resulsts: 349182
Page 5156 of 34,919
« previous page » next page
Filters