6.5

CVSS3.1

CVE-2025-3280 - ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes <= 1.4.9 - Authenticated (Subscri…

The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value_filter' parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient prepara…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 7:24 p.m.

5.3

CVSS3.1

CVE-2024-13307 - Reales WP - Real Estate WordPress Theme <= 2.1.2 - Missing Authorization to Unauthenticated Attachm…

The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'reales_delete_file', 'reales_delete_file_plans', 'reales_add_to_favourites', and 'reales_remove_from_favourites' functions in all ver…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 5:23 p.m.

7.2

CVSS3.1

CVE-2025-3300 - WPMasterToolKit (WPMTK) – All in one plugin <= 2.5.2 - Authenticated (Administrator+) to Arbitrary …

The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to read and modify the contents of arbitrary files on…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 7:24 p.m.

6.4

CVSS3.1

CVE-2025-3832 - FuseDesk <= 6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via successredirect Para…

The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access …

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 7:24 p.m.

6.4

CVSS3.1

CVE-2025-2579 - Lottie Player <= 1.1.8 - Authenticated (Author+) Stored Cross-Site Scripting via File Upload

The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inj…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 7:23 p.m.

8.8

CVSS3.1

CVE-2025-3607 - Frontend Login and Registration Blocks <= 1.0.8 - Authenticated (Subscriber+) Privilege Escalation …

The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.8. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it possible for authen…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 7:24 p.m.

9.8

CVSS3.1

CVE-2025-3604 - Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for unauthenticated a…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 6:24 p.m.

6.4

CVSS3.1

CVE-2025-2543 - Advanced Accordion Gutenberg Block <= 5.0.2 - Authenticated (Author+) Stored Cross-Site Scripting v…

The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 6:24 p.m.

4.3

CVSS3.1

CVE-2025-1284 - Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) <= 4.1 - Insecure…

The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1 via the xc_woo_printer_preview AJAX action due to missing validation on a user controlled key. This …

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 4:59 p.m.

8.8

CVSS3.1

CVE-2025-3101 - Configurator Theme Core <= 1.4.7 - Authenticated (Subscriber+) Privilege Escalation

The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.7. This is due to the plugin not properly validating user meta fields prior to updating them in the database. This makes it possible for authenticated attackers, with Sub…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 4:53 p.m.
Total resulsts: 343996
Page 5163 of 34,400
« previous page » next page
Filters