6.4

CVSS3.1

CVE-2025-13840 - BUKAZU Search widget <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'short…

The BUKAZU Search widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode' parameter of the 'bukazu_search' shortcode in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:20 a.m.

6.4

CVSS3.1

CVE-2025-13960 - GPXpress <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The GPXpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gpxpress' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, …

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:20 a.m.

6.8

CVSS3.1

CVE-2025-13320 - WP User Manager <= 2.9.12 - Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_a…

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_inpu…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:20 a.m.

5.3

CVSS3.1

CVE-2025-13440 - Premmerce Wishlist for WooCommerce <= 1.1.10 - Missing Authorization to Authenticated (Subscriber+)…

The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.10. This is due to a missing capability check on the deleteWishlist() function. This makes it possible for authenticated attackers, with Subscriber-level acce…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:20 a.m.

4.3

CVSS3.1

CVE-2025-14392 - Simple Theme Changer <= 1.0. - Missing Authorization to Plugin Settings Update via AJAX Actions

The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_theme_admin, display_method_admin, and set_change_theme_button_name actions actions in all versions up to, and including, 1.0. This makes it possible for au…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:20 a.m.

6.4

CVSS3.1

CVE-2025-14032 - Bold Timeline Lite <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' …

The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in the 'bold_timeline_group' shortcode in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated …

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:20 a.m.

6.4

CVSS3.1

CVE-2025-13969 - Reviews Sorted <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'space' Shor…

The Reviews Sorted plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'space' parameter of the [reviews-slider] shortcode in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:20 a.m.

4.3

CVSS3.1

CVE-2025-14161 - Truefy Embed <= 1.1.0 - Cross-Site Request Forgery to 'truefy_embed_options_update' Settings Update

The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the 'truefy_embed_options_update' settings update action. This makes it possible for unauthenticated attackers to update the plug…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:20 a.m.

4.3

CVSS3.1

CVE-2025-14354 - Resource Library for Logged In Users <= 1.4 - Cross-Site Request Forgery to Multiple Administrative…

The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various …

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:20 a.m.

4.3

CVSS3.1

CVE-2025-14165 - Kirim.Email WooCommerce Integration <= 1.2.9 - Cross-Site Request Forgery to Settings Update

The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9. This is due to missing nonce validation on the plugin's settings page. This makes it possible for unauthenticated attackers to modify the plugin's AP…

📅 Published: Dec. 12, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 12, 2025, 3:20 a.m.
Total resulsts: 322000
Page 7 of 32,200
« previous page » next page
Filters