9.8

CVSS3.1

CVE-2025-27270 - WordPress Residential Address Detection Plugin <= 2.5.4 - Arbitrary Option Update to Privilege Esca…

Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection allows Privilege Escalation.This issue affects Residential Address Detection: from n/a through <= 2.5.4.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

7.1

CVSS3.1

CVE-2025-27269 - WordPress .htaccess Login block Plugin <= 0.9a - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anton Aleksandrov .htaccess Login block htaccess-login-block allows Reflected XSS.This issue affects .htaccess Login block: from n/a through <= 0.9a.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

9.3

CVSS3.1

CVE-2025-27268 - WordPress Small Package Quotes – Worldwide Express Edition Plugin <= 5.2.18 - SQL Injection vulnera…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-quotes-wwe-edition allows SQL Injection.This issue affects Small Package Quotes – Worldwide Express Edition: from n/…

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2025-27264 - WordPress Doctor Appointment Booking Plugin <= 1.0.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creativeitem Doctor Appointment Booking doctor-appointment-booking allows PHP Local File Inclusion.This issue affects Doctor Appointment Booking: from n/a through <= 1.0.0.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

8.5

CVSS3.1

CVE-2025-27263 - WordPress Doctor Appointment Booking Plugin <= 1.0.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creativeitem Doctor Appointment Booking doctor-appointment-booking allows SQL Injection.This issue affects Doctor Appointment Booking: from n/a through <= 1.0.0.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

7.1

CVSS3.1

CVE-2025-26589 - WordPress IE CSS3 Support Plugin <= 2.0.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristopher Dino IE CSS3 Support ie-css3-support allows Reflected XSS.This issue affects IE CSS3 Support: from n/a through <= 2.0.1.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-26588 - WordPress TTT Crop Plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gabrielperezs TTT Crop ttt-crop allows Reflected XSS.This issue affects TTT Crop: from n/a through <= 1.0.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-26587 - WordPress sidebarTabs Plugin <= 3.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nghorta sidebarTabs sidebartabs allows Reflected XSS.This issue affects sidebarTabs: from n/a through <= 3.1.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-26586 - WordPress Events Planner Plugin <= 1.3.10 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in abelony Events Planner events-planner allows Reflected XSS.This issue affects Events Planner: from n/a through <= 1.3.10.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-26585 - WordPress DL Leadback Plugin <= 1.2.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DyadyaLesha DL Leadback dl-leadback allows Reflected XSS.This issue affects DL Leadback: from n/a through <= 1.2.1.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.
Total resulsts: 349182
Page 6478 of 34,919
Β« previous page Β» next page
Filters