7.1

CVSS3.1

CVE-2025-22307 - WordPress Product Table for WooCommerce plugin <= 4.0.3 - Reflected Cross Site Scripting (XSS) vuln…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam Product Table for WooCommerce woo-product-table allows Reflected XSS.This issue affects Product Table for WooCommerce: from n/a through <= 4.0.3.

πŸ“… Published: Jan. 9, 2025, 3:39 p.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

7.1

CVSS3.1

CVE-2025-22313 - WordPress Widgetize Pages Light plugin <= 3.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Reflected XSS.This issue affects Widgetize Pages Light: from n/a through <= 3.0.

πŸ“… Published: Jan. 9, 2025, 3:39 p.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

7.1

CVSS3.1

CVE-2025-22330 - WordPress MG Parallax Slider plugin <= 1.0. - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mahesh Waghmare MG Parallax Slider mg-parallax-slider allows Reflected XSS.This issue affects MG Parallax Slider: from n/a through <= 1.0..

πŸ“… Published: Jan. 9, 2025, 3:39 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-22331 - WordPress Cf7Save Extension plugin <= 1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in P3JX Cf7Save Extension cf7save-extension allows Reflected XSS.This issue affects Cf7Save Extension: from n/a through <= 1.

πŸ“… Published: Jan. 9, 2025, 3:39 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-22345 - WordPress TS Comfort DB plugin <= 2.0.7 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tsinf TS Comfort DB ts-comfort-database allows Reflected XSS.This issue affects TS Comfort DB: from n/a through <= 2.0.7.

πŸ“… Published: Jan. 9, 2025, 3:39 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-22361 - WordPress Opentracker Analytics Plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Opentracker Opentracker Analytics opentracker-analytics allows Reflected XSS.This issue affects Opentracker Analytics: from n/a through <= 1.3.

πŸ“… Published: Jan. 9, 2025, 3:39 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

10

CVSS3.1

CVE-2025-22504 - WordPress 4ECPS Web Forms Plugin <= 0.2.18 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in jumpdemand 4ECPS Web Forms 4ecps-webforms allows Upload a Web Shell to a Web Server.This issue affects 4ECPS Web Forms: from n/a through <= 0.2.18.

πŸ“… Published: Jan. 9, 2025, 3:39 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

8.5

CVSS3.1

CVE-2025-22505 - WordPress NC Wishlist for Woocommerce Plugin <= 1.0.1 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishlist for Woocommerce nc-wishlist-for-woocommerce allows SQL Injection.This issue affects NC Wishlist for Woocommerce: from n/a through <= 1.0.1.

πŸ“… Published: Jan. 9, 2025, 3:39 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

8.1

CVSS3.1

CVE-2025-22508 - WordPress FAT Event Lite plugin <= 1.1 - Unauthenticated Non-Arbitrary Local File Inclusion vulnera…

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Event Lite fat-event-lite allows PHP Local File Inclusion.This issue affects FAT Event Lite: from n/a through <= 1.1.

πŸ“… Published: Jan. 9, 2025, 3:39 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.2

CVSS3.1

CVE-2025-22510 - WordPress WC Price History for Omnibus plugin <= 2.1.4 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Object Injection.This issue affects WC Price History for Omnibus: from n/a through <= 2.1.4.

πŸ“… Published: Jan. 9, 2025, 3:39 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.
Total resulsts: 346533
Page 6939 of 34,654
Β« previous page Β» next page
Filters