6.4

CVSS3.1

CVE-2025-4588 - 360 Photo Spheres <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta…

📅 Published: Aug. 2, 2025, 7:24 a.m. 🔄 Last Modified: Aug. 2, 2025, 8:15 a.m.

6.4

CVSS3.1

CVE-2025-8212 - Medical Addon for Elementor <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter widget in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Aug. 2, 2025, 7:24 a.m. 🔄 Last Modified: Aug. 2, 2025, 8:15 a.m.

5.3

CVSS3.1

CVE-2025-8152 - WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons <= 1.7.0 - Missing Authorization to Unau…

The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_cta_status' and 'change_sticky_sidebar_name' functions in all versions up to, and including, 1.7.0. This makes it p…

📅 Published: Aug. 2, 2025, 7:24 a.m. 🔄 Last Modified: Aug. 2, 2025, 8:15 a.m.

4.4

CVSS3.1

CVE-2025-6626 - ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.10.4 - Authenticated (Adminis…

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenti…

📅 Published: Aug. 2, 2025, 7:24 a.m. 🔄 Last Modified: Aug. 2, 2025, 8:15 a.m.

8.8

CVSS3.1

CVE-2025-6754 - SEO Metrics <= 1.0.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function in versions 1.0.5 through 1.0.15. Because the AJAX action only veri…

📅 Published: Aug. 2, 2025, 7:24 a.m. 🔄 Last Modified: Aug. 2, 2025, 8:15 a.m.

6.4

CVSS3.1

CVE-2025-8146 - Qi Addons for Elementor <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typ…

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut Text widget in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic…

📅 Published: Aug. 2, 2025, 4:24 a.m. 🔄 Last Modified: Aug. 2, 2025, 5:15 a.m.

6.8

CVSS3.1

CVE-2025-7694 - Woffice Core <= 5.4.26 - Authenticated (Contributor+) Arbitrary File Deletion

The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_delete() function in all versions up to, and including, 5.4.26. This makes it possible for authenticated attackers, with Contributor-level access and a…

📅 Published: Aug. 2, 2025, 3:28 a.m. 🔄 Last Modified: Aug. 2, 2025, 4:15 a.m.

0.0

CVE-2025-6078 - CVE-2025-6078

Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but does not completely sanitize input, making it possible to add notes with HTML tags and JavaScript, enabling an attacker to add a note cont…

📅 Published: Aug. 2, 2025, 2:15 a.m. 🔄 Last Modified: Aug. 2, 2025, 3:15 a.m.

0.0

CVE-2025-6077 - CVE-2025-6077

Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.

📅 Published: Aug. 2, 2025, 2:15 a.m. 🔄 Last Modified: Aug. 2, 2025, 3:15 a.m.

0.0

CVE-2025-6076 - CVE-2025-6076

Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compromise the device. By default, the software runs as SYSTEM, heightening the severity of the vulnerab…

📅 Published: Aug. 2, 2025, 2:15 a.m. 🔄 Last Modified: Aug. 2, 2025, 3:15 a.m.
Total resulsts: 304064
Page 7 of 30,407
« previous page » next page
Filters