9.8

CVSS3.1

CVE-2025-46247 - WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerability

Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.

πŸ“… Published: April 22, 2025, 9:53 a.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

8.8

CVSS3.1

CVE-2025-46246 - WordPress CM Answers plugin <= 3.3.3 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Request Forgery.This issue affects CM Answers: from n/a through <= 3.3.3.

πŸ“… Published: April 22, 2025, 9:53 a.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

8.8

CVSS3.1

CVE-2025-46245 - WordPress CM Ad Changer plugin <= 2.0.5 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site Request Forgery.This issue affects CM Ad Changer: from n/a through <= 2.0.5.

πŸ“… Published: April 22, 2025, 9:53 a.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

9.8

CVSS3.1

CVE-2025-46244 - WordPress Advanced Linked Variations for Woocommerce plugin <= 1.0.3 - Broken Access Control Vulner…

Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Linked Variations for Woocommerce: from n/a through <= 1.0.3.

πŸ“… Published: April 22, 2025, 9:53 a.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

8.8

CVSS3.1

CVE-2025-46243 - WordPress Recover abandoned cart for WooCommerce plugin <= 2.2 - Cross Site Request Forgery (CSRF) …

Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abandoned-cart allows Cross Site Request Forgery.This issue affects Recover abandoned cart for WooCommerce: from n/a through <= 2.2.

πŸ“… Published: April 22, 2025, 9:53 a.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

4.9

CVSS3.1

CVE-2025-46242 - WordPress Watu Quiz plugin <= 3.4.3 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu allows SQL Injection.This issue affects Watu Quiz: from n/a through <= 3.4.3.

πŸ“… Published: April 22, 2025, 9:53 a.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

8.8

CVSS3.1

CVE-2025-46241 - WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.

πŸ“… Published: April 22, 2025, 9:53 a.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

5.4

CVSS3.1

CVE-2025-46240 - WordPress Simple Download Counter plugin <= 2.2 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter simple-download-counter allows Stored XSS.This issue affects Simple Download Counter: from n/a through <= 2.2.

πŸ“… Published: April 22, 2025, 9:53 a.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

5.4

CVSS3.1

CVE-2025-46239 - WordPress Theme Switcha plugin <= 3.4 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme Switcha theme-switcha allows Stored XSS.This issue affects Theme Switcha: from n/a through <= 3.4.

πŸ“… Published: April 22, 2025, 9:53 a.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

5.4

CVSS3.1

CVE-2025-46238 - WordPress List Last Changes plugin <= 1.2.1 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer List Last Changes list-last-changes allows Stored XSS.This issue affects List Last Changes: from n/a through <= 1.2.1.

πŸ“… Published: April 22, 2025, 9:53 a.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.
Total resulsts: 345139
Page 5293 of 34,514
Β« previous page Β» next page
Filters