5.3
CVE-2025-23764 - WordPress Copy Move Posts plugin <= 1.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in ujjavaljani Copy Move Posts copy-move-posts.This issue affects Copy Move Posts: from n/a through <= 1.6.
6.5
CVE-2025-23816 - WordPress Metaphor Widgets plugin <= 2.4 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaphorcreations Metaphor Widgets mtphr-widgets allows Stored XSS.This issue affects Metaphor Widgets: from n/a through <= 2.4.
7.1
CVE-2025-23815 - WordPress root Cookie plugin <= 1.6 - CSRF to Stored XSS vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in linickx root Cookie root-cookie allows Cross Site Request Forgery.This issue affects root Cookie: from n/a through <= 1.6.
7.1
CVE-2025-23793 - WordPress Auto FTP plugin <= 1.0.1 - CSRF to Stored Cross-Site Scripting vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Turcu Auto FTP auto-ftp allows Stored XSS.This issue affects Auto FTP: from n/a through <= 1.0.1.
5.4
CVE-2025-23761 - WordPress Woo Tuner plugin <= 0.1.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Alex Volkov Woo Tuner woo-tuner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Tuner: from n/a through <= 0.1.2.
7.1
CVE-2025-23760 - WordPress Chatter plugin <= 1.0.1 - CSRF to Stored XSS vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Volkov Chatter chatter allows Stored XSS.This issue affects Chatter: from n/a through <= 1.0.1.
4.3
CVE-2025-23957 - WordPress Sur.ly plugin <= 3.0.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in surdotly Sur.ly surly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sur.ly: from n/a through <= 3.0.3.
6.5
CVE-2025-23965 - WordPress Kopa Nictitate Toolkit plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kopatheme Kopa Nictitate Toolkit kopa-nictitate-toolkit allows Stored XSS.This issue affects Kopa Nictitate Toolkit: from n/a through <= 1.0.2.
5.4
CVE-2025-23961 - WordPress WordPress Graphs & Charts Plugin <= 2.0.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in wptasker WordPress Graphs & Charts graph-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Graphs & Charts: from n/a through <= 2.0.8.
4.3
CVE-2025-23955 - WordPress Xola plugin <= 1.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in xola Xola xola-bookings-for-tours-activities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xola: from n/a through <= 1.6.