8.5

CVSS3.1

CVE-2025-32687 - WordPress Review Stars Count For WooCommerce plugin <= 2.0 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magnigenie Review Stars Count For WooCommerce review-stars-count-for-woocommerce allows SQL Injection.This issue affects Review Stars Count For WooCommerce: from n/a through <= 2.0.

πŸ“… Published: April 10, 2025, 8:09 a.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

8.1

CVSS3.1

CVE-2025-32668 - WordPress Real Estate Manager plugin <= 7.3 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows PHP Local File Inclusion.This issue affects Real Estate Manager: from n/a through <= 7.3.

πŸ“… Published: April 10, 2025, 8:09 a.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

6

CVSS4.0

CVE-2024-38865 - Livestatus command injection in RestAPI

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for …

πŸ“… Published: April 10, 2025, 7:35 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 9:56 p.m.

8.8

CVSS3.1

CVE-2025-3417 - Embedder 1.3 - 1.3.5 - Authenticated (Subscriber+) Arbitrary Options Update

The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_set_global_option() function in versions 1.3 to 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level a…

πŸ“… Published: April 10, 2025, 7:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2024-13909 - Accredible Certificates & Open Badges <= 1.4.9 - Authenticated (Administrator+) SQL Injection via o…

The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

πŸ“… Published: April 10, 2025, 7:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-2805 - ORDER POST <= 2.0.2 - Unauthenticated Arbitrary Shortcode Execution

The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthentic…

πŸ“… Published: April 10, 2025, 7:02 a.m. πŸ”„ Last Modified: April 20, 2026, 11:30 p.m.

6.5

CVSS3.1

CVE-2025-2719 - Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swa…

The Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swatches) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in versions 1.2.8 to 1.4.0. This makes…

πŸ“… Published: April 10, 2025, 7:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-2809 - azurecurve Shortcodes in Comments <= 2.0.2 - Unauthenticated Arbitrary Shortcode Execution

The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it p…

πŸ“… Published: April 10, 2025, 7:02 a.m. πŸ”„ Last Modified: April 22, 2026, 5:45 p.m.

6.4

CVSS3.1

CVE-2024-10894 - Payment Forms for Paystack <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'datepicker', 'textarea', and 'text' in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. …

πŸ“… Published: April 10, 2025, 7:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-13896 - WP-GeSHi-Highlight <= 1.4.3 - Author+ ReDoS

The WP-GeSHi-Highlight β€” rock-solid syntax highlighting for 259 languages WordPress plugin through 1.4.3 processes user-supplied input as a regular expression via the wp_geshi_filter_replace_code() function, which could lead to Regular Expression Denial of Service (ReDoS) issue

πŸ“… Published: April 10, 2025, 6 a.m. πŸ”„ Last Modified: Aug. 27, 2025, noon
Total resulsts: 349182
Page 5924 of 34,919
Β« previous page Β» next page
Filters