4.3

CVSS3.1

CVE-2025-22722 - WordPress Widget Options plugin <= 4.0.8 - Broken Access Control to Notice Dimissal vulnerability

Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widget Options: from n/a through <= 4.0.8.

πŸ“… Published: Jan. 21, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

4.3

CVSS3.1

CVE-2025-22721 - WordPress ApplyOnline plugin <= 2.6.7.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Farhan Noor ApplyOnline apply-online allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ApplyOnline: from n/a through <= 2.6.7.1.

πŸ“… Published: Jan. 21, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

6.5

CVSS3.1

CVE-2025-22661 - WordPress Online Payments plugin <= 3.20.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Payments – Get Paid with PayPal, Square & Stripe paypal-payment-button-by-vcita allows Stored XSS.This issue affects Online Payments – Get Paid with PayPal, Square & Stripe: from n/a t…

πŸ“… Published: Jan. 21, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

5.9

CVSS3.1

CVE-2025-22276 - WordPress Related Post Shortcode Plugin <= 1.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enguerranws Related Post Shortcode related-post-shortcode allows Stored XSS.This issue affects Related Post Shortcode: from n/a through <= 1.2.

πŸ“… Published: Jan. 21, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

6.5

CVSS3.1

CVE-2025-22267 - WordPress Weaver Themes Shortcode Compatibility Plugin <= 1.0.4 - Cross Site Scripting (XSS) vulner…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweaver Weaver Themes Shortcode Compatibility weaver-themes-shortcode-compatibility allows Stored XSS.This issue affects Weaver Themes Shortcode Compatibility: from n/a through <= 1.0.4.

πŸ“… Published: Jan. 21, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

7.1

CVSS3.1

CVE-2025-23580 - WordPress BizLibrary plugin <= 1.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew BizLibrary bizlibrary allows Reflected XSS.This issue affects BizLibrary: from n/a through <= 1.1.

πŸ“… Published: Jan. 21, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:24 p.m.

7.1

CVSS3.1

CVE-2025-23551 - WordPress SexBundle plugin <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in razvypp SexBundle sexbundle allows Reflected XSS.This issue affects SexBundle: from n/a through <= 1.4.

πŸ“… Published: Jan. 21, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:24 p.m.

7.1

CVSS3.1

CVE-2025-23489 - WordPress WP-Announcements plugin <= 1.8 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Messenlehner WP-Announcements wp-announcements allows Reflected XSS.This issue affects WP-Announcements: from n/a through <= 1.8.

πŸ“… Published: Jan. 21, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

8.2

CVSS3.1

CVE-2025-23477 - WordPress Realty Workstation plugin <= 1.0.45 - Broken Access Control vulnerability

Missing Authorization vulnerability in realtyworkstation Realty Workstation realty-workstation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Realty Workstation: from n/a through <= 1.0.45.

πŸ“… Published: Jan. 21, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-23461 - WordPress Social2Blog plugin <= 0.2.990 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xkollsoftware Social2Blog social2blog allows Reflected XSS.This issue affects Social2Blog: from n/a through <= 0.2.990.

πŸ“… Published: Jan. 21, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.
Total resulsts: 346529
Page 6760 of 34,653
Β« previous page Β» next page
Filters