6.5

CVSS3.1

CVE-2025-30818 - WordPress jAlbum Bridge plugin <= 2.0.17 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mlaza jAlbum Bridge jalbum-bridge allows DOM-Based XSS.This issue affects jAlbum Bridge: from n/a through <= 2.0.17.

๐Ÿ“… Published: March 27, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

5.4

CVSS3.1

CVE-2025-30817 - WordPress Z Companion plugin <= 1.0.13 - Broken Access Control vulnerability

Missing Authorization vulnerability in wpzita Z Companion z-companion allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Z Companion: from n/a through <= 1.0.13.

๐Ÿ“… Published: March 27, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

4.3

CVSS3.1

CVE-2025-30816 - WordPress publish post email notification plugin <= 1.0.2.3 - Cross Site Request Forgery (CSRF) to โ€ฆ

Cross-Site Request Forgery (CSRF) vulnerability in Nks publish post email notification publish-post-email-notification allows Cross Site Request Forgery.This issue affects publish post email notification: from n/a through <= 1.0.2.3.

๐Ÿ“… Published: March 27, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

4.3

CVSS3.1

CVE-2025-30815 - WordPress Hesabfa Accounting plugin <= 2.1.8 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Saeed Sattar Beglou Hesabfa Accounting hesabfa-accounting allows Cross Site Request Forgery.This issue affects Hesabfa Accounting: from n/a through <= 2.1.8.

๐Ÿ“… Published: March 27, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

7.5

CVSS3.1

CVE-2025-30814 - WordPress The Post Grid plugin <= 7.7.17 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme The Post Grid the-post-grid allows PHP Local File Inclusion.This issue affects The Post Grid: from n/a through <= 7.7.17.

๐Ÿ“… Published: March 27, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

6.5

CVSS3.1

CVE-2025-30813 - WordPress Listamester plugin <= 2.3.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in listamester Listamester listamester allows Stored XSS.This issue affects Listamester: from n/a through <= 2.3.5.

๐Ÿ“… Published: March 27, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

6.5

CVSS3.1

CVE-2025-30812 - WordPress SKT Addons for Elementor plugin <= 3.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Addons for Elementor skt-addons-for-elementor allows Stored XSS.This issue affects SKT Addons for Elementor: from n/a through <= 3.5.

๐Ÿ“… Published: March 27, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

4.3

CVSS3.1

CVE-2025-30811 - WordPress ValidateCertify plugin <= 1.6.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify validar-certificados-de-cursos allows Cross Site Request Forgery.This issue affects ValidateCertify: from n/a through <= 1.6.1.

๐Ÿ“… Published: March 27, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

8.5

CVSS3.1

CVE-2025-30810 - WordPress Lead Form Data Collection to CRM plugin <= 3.0.1 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Blind SQL Injection.This issue affects Lead Form Data Collection to CRM: from n/a through <= 3.0.1.

๐Ÿ“… Published: March 27, 2025, 10:54 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

5.4

CVSS3.1

CVE-2025-30809 - WordPress WordPress Contact Form, Drag and Drop Form Builder Plugin โ€“ Live Forms plugin <= 4.8.4 - โ€ฆ

Missing Authorization vulnerability in Shahjada Live Forms liveforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Forms: from n/a through <= 4.8.4.

๐Ÿ“… Published: March 27, 2025, 10:54 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.
Total resulsts: 349182
Page 6176 of 34,919
ยซ previous page ยป next page
Filters