8.5

CVSS3.1

CVE-2025-26915 - WordPress Wishlist Plugin <= 1.0.41 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Injection.This issue affects Wishlist: from n/a through <= 1.0.41.

๐Ÿ“… Published: Feb. 25, 2025, 2:17 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

6.5

CVSS3.1

CVE-2025-26913 - WordPress AR for WordPress plugin <= 7.7 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webandprint AR For WordPress ar-for-wordpress allows DOM-Based XSS.This issue affects AR For WordPress: from n/a through <= 7.7.

๐Ÿ“… Published: Feb. 25, 2025, 2:17 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

6.5

CVSS3.1

CVE-2025-26912 - WordPress Easy Elementor Addons plugin <= 2.1.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy Elementor Addons easy-elementor-addons allows Stored XSS.This issue affects Easy Elementor Addons: from n/a through <= 2.1.6.

๐Ÿ“… Published: Feb. 25, 2025, 2:17 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

4.3

CVSS3.1

CVE-2025-26911 - WordPress System Dashboard plugin <= 2.8.18 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo System Dashboard system-dashboard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects System Dashboard: from n/a through <= 2.8.18.

๐Ÿ“… Published: Feb. 25, 2025, 2:17 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2025-26907 - WordPress Estatik Mortgage Calculator plugin <= 2.0.12 - Local File Inclusion vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatik Mortgage Calculator Estatik estatik-mortgage-calculator allows Stored XSS.This issue affects Mortgage Calculator Estatik: from n/a through <= 2.0.12.

๐Ÿ“… Published: Feb. 25, 2025, 2:17 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2025-26905 - WordPress Estatik plugin <= 4.3.0 - Local File Inclusion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estatik Estatik estatik allows PHP Local File Inclusion.This issue affects Estatik: from n/a through <= 4.3.0.

๐Ÿ“… Published: Feb. 25, 2025, 2:17 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:11 p.m.

6.5

CVSS3.1

CVE-2025-26904 - WordPress WP Responsive Auto Fit Text plugin <= 0.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gal_op WP Responsive Auto Fit Text wp-responsive-slab-text allows DOM-Based XSS.This issue affects WP Responsive Auto Fit Text: from n/a through <= 0.2.

๐Ÿ“… Published: Feb. 25, 2025, 2:17 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

9.8

CVSS3.1

CVE-2025-26900 - WordPress Flexmlsยฎ IDX Plugin Plugin <= 3.14.27 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in flexmls Flexmlsยฎ IDX flexmls-idx allows Object Injection.This issue affects Flexmlsยฎ IDX: from n/a through <= 3.14.27.

๐Ÿ“… Published: Feb. 25, 2025, 2:17 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

6.5

CVSS3.1

CVE-2025-26897 - WordPress List Related Attachments plugin <= 2.1.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Baden List Related Attachments list-related-attachments-widget allows DOM-Based XSS.This issue affects List Related Attachments: from n/a through <= 2.1.6.

๐Ÿ“… Published: Feb. 25, 2025, 2:17 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

6.5

CVSS3.1

CVE-2025-26896 - WordPress PiwigoPress plugin <= 2.33 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vpiwigo PiwigoPress piwigopress allows Stored XSS.This issue affects PiwigoPress: from n/a through <= 2.33.

๐Ÿ“… Published: Feb. 25, 2025, 2:17 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.
Total resulsts: 349182
Page 6636 of 34,919
ยซ previous page ยป next page
Filters