7.1
CVE-2025-32524 - WordPress MyWorks WooCommerce Sync for QuickBooks Online plugin <= 2.9.1 - Reflected Cross Site Scrβ¦
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyWorks MyWorks WooCommerce Sync for QuickBooks Online myworks-woo-sync-for-quickbooks-online allows Reflected XSS.This issue affects MyWorks WooCommerce Sync for QuickBooks Online: from n/a througβ¦
7.1
CVE-2025-32523 - WordPress WooCommerce β Payphone Gateway plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) vulβ¦
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in payphone WooCommerce β Payphone Gateway wc-payphone-gateway allows Reflected XSS.This issue affects WooCommerce β Payphone Gateway: from n/a through <= 3.2.0.
8.1
CVE-2025-32519 - WordPress IDonate plugin <= 2.1.18 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Foysal Imran IDonate idonate allows PHP Local File Inclusion.This issue affects IDonate: from n/a through <= 2.1.18.
7.1
CVE-2025-32517 - WordPress MultiMailer plugin <= 1.0.3 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SCAND MultiMailer scand-multi-mailer allows Reflected XSS.This issue affects MultiMailer: from n/a through <= 1.0.3.
7.5
CVE-2025-32509 - WordPress Simple WP Events plugin <= 1.8.17 - Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMinds Simple WP Events simple-wp-events allows Path Traversal.This issue affects Simple WP Events: from n/a through <= 1.8.17.
0.0
CVE-2025-32491 - WordPress Rankology SEO β On-site SEO plugin <= 2.2.4 - Privilege Escalation Vulnerability
Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO β On-site SEO rankology-seo-all-in-one-seo-analytics allows Privilege Escalation.This issue affects Rankology SEO β On-site SEO: from n/a through <= 2.2.4.
8.8
CVE-2025-32144 - WordPress Job Board Manager Plugin <= 2.1.61 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager job-board-manager allows Object Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.
8.8
CVE-2025-32143 - WordPress Accordion plugin <= 2.3.11 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in PickPlugins Accordion accordions allows Object Injection.This issue affects Accordion: from n/a through <= 2.3.11.
9.3
CVE-2025-31599 - WordPress Bulk Product Sync plugin <= 8.6 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Product Sync sync-wc-google allows SQL Injection.This issue affects Bulk Product Sync: from n/a through <= 8.6.
9.3
CVE-2025-31565 - WordPress WPSmartContracts plugin <= 2.0.12 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez WPSmartContracts wp-smart-contracts allows Blind SQL Injection.This issue affects WPSmartContracts: from n/a through <= 2.0.12.