6.4

CVSS3.1

CVE-2025-1664 - Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Co…

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Parallax slider in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for aut…

📅 Published: March 8, 2025, 11:16 a.m. 🔄 Last Modified: April 8, 2026, 4:58 p.m.

8.8

CVSS3.1

CVE-2024-11640 - VikRentCar Car Rental Management System <= 1.4.2 - Cross-Site Request Forgery to Authenticated (Sub…

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to change plugi…

📅 Published: March 8, 2025, 11:16 a.m. 🔄 Last Modified: April 8, 2026, 4:50 p.m.

6.4

CVSS3.1

CVE-2024-13649 - 140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.7 - Authenticated (Contributor+) Stored Cr…

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.4.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit…

📅 Published: March 8, 2025, 11:16 a.m. 🔄 Last Modified: April 8, 2026, 4:49 p.m.

6.4

CVSS3.1

CVE-2025-1783 - Gallery Styles <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Gallery Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery Block in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and ab…

📅 Published: March 8, 2025, 9:22 a.m. 🔄 Last Modified: April 8, 2026, 5:21 p.m.

4.3

CVSS3.1

CVE-2025-1322 - WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Prote…

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the 'feed' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attac…

📅 Published: March 8, 2025, 9:22 a.m. 🔄 Last Modified: April 8, 2026, 5:21 p.m.

7.5

CVSS3.1

CVE-2025-1323 - WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Unauthenticated SQL Injection

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL q…

📅 Published: March 8, 2025, 9:22 a.m. 🔄 Last Modified: April 8, 2026, 5:15 p.m.

6.3

CVSS3.1

CVE-2025-1325 - WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Missing Authorization to Authentic…

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the 'rcl_preview_post' AJAX endpoint in all versions up to, and including, 16.26.10. This makes it possible for authenticated attackers, wi…

📅 Published: March 8, 2025, 9:22 a.m. 🔄 Last Modified: April 8, 2026, 5:15 p.m.

8.1

CVSS3.1

CVE-2024-13359 - Product Input Fields for WooCommerce <= 1.12.0 - Unauthenticated Limited File Upload

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function in all versions up to, and including, 1.12.0. This may make it possible for unauthenticated at…

📅 Published: March 8, 2025, 9:22 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

6.4

CVSS3.1

CVE-2025-1324 - WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Store…

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'public-form' shortcode in all versions up to, and including, 16.26.10 due to insufficient input sanitization and output escaping on user supplied attributes. Th…

📅 Published: March 8, 2025, 9:22 a.m. 🔄 Last Modified: April 8, 2026, 4:47 p.m.

6.4

CVSS3.1

CVE-2025-1287 - The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <…

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown, Syntax Highlighter, and Page Scroll widgets in all versions up to, and including, 6.2.2 due to insufficient inpu…

📅 Published: March 8, 2025, 8:22 a.m. 🔄 Last Modified: April 8, 2026, 5:34 p.m.
Total resulsts: 343921
Page 5885 of 34,393
« previous page » next page
Filters