7.2

CVSS3.1

CVE-2024-13906 - Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authentica…

The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.7.3 via deserialization of untrusted input in the 'import_gallery_from_csv' function. This makes it possible for authe…

📅 Published: March 7, 2025, 7:22 a.m. 🔄 Last Modified: April 8, 2026, 5:01 p.m.

8.8

CVSS3.1

CVE-2025-1309 - UiPress lite | Effortless custom dashboards, admin themes and pages <= 3.5.04 - Missing Authorizati…

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the uip_save_form_as_option() function in all versions up to, and including, 3.5…

📅 Published: March 7, 2025, 7:22 a.m. 🔄 Last Modified: April 8, 2026, 4:58 p.m.

6.4

CVSS3.1

CVE-2025-0863 - Flexmls® IDX <= 3.14.27 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' shortcode in all versions up to, and including, 3.14.27 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic…

📅 Published: March 7, 2025, 7:22 a.m. 🔄 Last Modified: April 8, 2026, 4:40 p.m.

7.5

CVSS3.1

CVE-2024-13320 - CURCY - WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection

The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the 'wc_filter_price_meta[where]' parameter in all versions up to, and including, 2.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o…

📅 Published: March 7, 2025, 6:40 a.m. 🔄 Last Modified: April 8, 2026, 4:59 p.m.

8.1

CVSS3.1

CVE-2024-13655 - Flex Mag - Responsive WordPress News Theme <= 3.5.2 - Missing Authorization to Authenticated (Subsc…

The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to, and including, 3.5.2. This makes it possibl…

📅 Published: March 7, 2025, 6:40 a.m. 🔄 Last Modified: April 8, 2026, 4:42 p.m.

6.4

CVSS3.1

CVE-2024-12809 - Wishlist <= 1.0.43 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortcode in all versions up to, and including, 1.0.43 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a…

📅 Published: March 7, 2025, 6:40 a.m. 🔄 Last Modified: April 8, 2026, 4:38 p.m.

9.8

CVSS3.1

CVE-2025-1475 - WPCOM Member <= 1.7.5 - Authentication Bypass via 'user_phone'

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone' parameter when logging in. This makes it possible for unauthenticated attackers to log in as any existing user on th…

📅 Published: March 7, 2025, 6:40 a.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.

6.9

CVSS4.0

CVE-2025-2067 - projectworlds Life Insurance Management System search.php sql injection

A vulnerability was found in projectworlds Life Insurance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /search.php. The manipulation of the argument key leads to sql injection. The attack may be initiated remotely. The exploit has been dis…

📅 Published: March 7, 2025, 4:31 a.m. 🔄 Last Modified: May 14, 2025, 4:14 p.m.

6.9

CVSS4.0

CVE-2025-2066 - projectworlds Life Insurance Management System updateAgent.php sql injection

A vulnerability has been found in projectworlds Life Insurance Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /updateAgent.php. The manipulation of the argument agent_id leads to sql injection. The attack can be initiated remotely. The exploit …

📅 Published: March 7, 2025, 4:31 a.m. 🔄 Last Modified: May 14, 2025, 4:14 p.m.

6.9

CVSS4.0

CVE-2025-2065 - projectworlds Life Insurance Management System editAgent.php sql injection

A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0. This affects an unknown part of the file /editAgent.php. The manipulation of the argument agent_id leads to sql injection. It is possible to initiate the attack remotely. The exploit …

📅 Published: March 7, 2025, 4 a.m. 🔄 Last Modified: May 14, 2025, 4:15 p.m.
Total resulsts: 343448
Page 5848 of 34,345
« previous page » next page
Filters