7.2

CVSS3.1

CVE-2025-1913 - Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via fo…

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via deserialization of untrusted input from the 'form_data' parameter This makes it possible for authenticated attackers…

📅 Published: March 26, 2025, 11:55 a.m. 🔄 Last Modified: April 21, 2026, 9:45 p.m.

2.7

CVSS3.1

CVE-2025-1911 - Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrato…

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.5.0. This makes it possible for authenticated a…

📅 Published: March 26, 2025, 11:55 a.m. 🔄 Last Modified: April 20, 2026, 11:30 p.m.

7.6

CVSS3.1

CVE-2025-1912 - Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request…

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the validate_file() Function. This makes it possible for authenticated attackers, with Administrator-level ac…

📅 Published: March 26, 2025, 11:55 a.m. 🔄 Last Modified: April 21, 2026, 9:45 p.m.

6.4

CVSS3.1

CVE-2025-1312 - Ultimate Blocks – WordPress Blocks Plugin <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site…

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttonTextColor’ parameter in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack…

📅 Published: March 26, 2025, 11:22 a.m. 🔄 Last Modified: April 20, 2026, 11:30 p.m.

6.4

CVSS3.1

CVE-2024-13411 - Zapier for WordPress <= 1.5.1 - Authenticated (Subscriber+) Blind Server-Side Request Forgery via u…

The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5.1 via the updated_user() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locat…

📅 Published: March 26, 2025, 11:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-13889 - WordPress Importer <= 0.8.3 - Authenticated (Administrator+) PHP Object Injection

The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of untrusted input in the 'maybe_unserialize' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to…

📅 Published: March 26, 2025, 11:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-1769 - Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrato…

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and…

📅 Published: March 26, 2025, 11:22 a.m. 🔄 Last Modified: April 21, 2026, 9:45 p.m.

8.8

CVSS3.1

CVE-2025-2110 - WP Compress <= 6.30.15 - Authenticated (Subscriber+) Missing Authorization via Multiple Functions

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its AJAX functions in all versions up to, and including, 6.30.15. This makes it possible for authenticated …

📅 Published: March 26, 2025, 11:22 a.m. 🔄 Last Modified: April 8, 2026, 4:43 p.m.

4

CVSS3.1

CVE-2025-27552 - DBIx::Class::EncodedColumn until 0.00032 for Perl uses insecure rand() function for salting passwor…

DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This vulnerability is associated with program files Crypt/Eksblowfish/Bcrypt.pm. This issue affects DBIx::Class::EncodedColumn until 0.00032.

📅 Published: March 26, 2025, 11:08 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2025-27551 - DBIx::Class::EncodedColumn until 0.00032 for Perl uses insecure rand() function for salting passwor…

DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This vulnerability is associated with program files lib/DBIx/Class/EncodedColumn/Digest.pm. This issue affects DBIx::Class::EncodedColumn until 0.00032.

📅 Published: March 26, 2025, 11:07 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6211 of 34,919
« previous page » next page
Filters