6.5
CVE-2025-32241 - WordPress Official CleverReach WooCommerce Integration plugin <= 3.4.6 - CSRF to Settings Change vuโฆ
Cross-Site Request Forgery (CSRF) vulnerability in CleverReachยฎ Official CleverReach Plugin for WooCommerce cleverreach-wc allows Cross Site Request Forgery.This issue affects Official CleverReach Plugin for WooCommerce: from n/a through <= 3.4.6.
4.3
CVE-2025-32238 - WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Sensitive Dโฆ
Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Retrieve Embedded Sensitive Data.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/aโฆ
4.3
CVE-2025-32237 - WordPress MasterStudy LMS plugin <= 3.5.28 - Broken Access Control vulnerability
Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from n/a through <= 3.5.28.
4.3
CVE-2025-32235 - WordPress MP3 Audio Player โ Music Player, Podcast Player & Radio by Sonaar plugin <= 5.9.4 - Brokeโฆ
Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.9.4.
4.3
CVE-2025-32234 - WordPress AdMail plugin <= 1.7.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in aleswebs AdMail โ Multilingual Back in-Stock Notifier for WooCommerce admail allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AdMail โ Multilingual Back in-Stock Notifier for WooCommerce: from n/a through <= 1.7.0.
4.3
CVE-2025-32233 - WordPress Revive.so plugin <= 2.0.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in WP Chill Revive.so revive-so allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive.so: from n/a through <= 2.0.3.
4.3
CVE-2025-32232 - WordPress StaffList plugin <= 3.2.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in ERA404 StaffList stafflist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects StaffList: from n/a through <= 3.2.7.
4.3
CVE-2025-32231 - WordPress Bookingor plugin <= 2.0.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Bookingor Bookingor bookingor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bookingor: from n/a through <= 2.0.1.
4.3
CVE-2025-32229 - WordPress Variable Inspector plugin <= 2.6.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in Bowo Variable Inspector variable-inspector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Variable Inspector: from n/a through <= 2.6.3.
4.3
CVE-2025-32226 - WordPress Display product variations dropdown on shop page plugin <= 1.1.3 - Broken Access Control โฆ
Missing Authorization vulnerability in Anzar Ahmed Display product variations dropdown on shop page display-product-variations-dropdown-on-shop-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display product variations dropdown on shop page: from n/a โฆ