4.3

CVSS3.1

CVE-2025-14077 - Simcast <= 1.0.0 - Cross-Site Request Forgery to Settings Update

The Simcast plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the settingsPage function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged re…

📅 Published: Jan. 7, 2026, 9:21 a.m. 🔄 Last Modified: Jan. 8, 2026, 6:08 p.m.

6.4

CVSS3.1

CVE-2025-15058 - Responsive Pricing Table <= 5.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via '…

The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'table_currency' parameter in all versions up to, and including, 5.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contrib…

📅 Published: Jan. 7, 2026, 9:21 a.m. 🔄 Last Modified: Jan. 8, 2026, 6:08 p.m.

6.4

CVSS3.1

CVE-2025-14114 - 1180px Shortcodes <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' S…

The 1180px Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-le…

📅 Published: Jan. 7, 2026, 9:21 a.m. 🔄 Last Modified: Jan. 8, 2026, 6:08 p.m.

5.3

CVSS3.1

CVE-2025-14460 - Piraeus Bank WooCommerce Payment Gateway <= 3.1.4 - Missing Authorization to Unauthenticated Arbitr…

The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modification in all versions up to, and including, 3.1.4. This is due to missing authorization checks on the payment callback endpoint handler when processing the 'fail' callback from the pa…

📅 Published: Jan. 7, 2026, 9:21 a.m. 🔄 Last Modified: Jan. 8, 2026, 6:08 p.m.

6.4

CVSS3.1

CVE-2025-14122 - AD Sliding FAQ <= 2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attr…

The AD Sliding FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliding_faq' shortcode in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, …

📅 Published: Jan. 7, 2026, 9:21 a.m. 🔄 Last Modified: Jan. 8, 2026, 6:08 p.m.

4.4

CVSS3.1

CVE-2025-13974 - Email Customizer for WooCommerce | Drag and Drop Email Templates Builder <= 2.6.7 - Authenticated (…

The Email Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email template content in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administ…

📅 Published: Jan. 7, 2026, 9:21 a.m. 🔄 Last Modified: Jan. 8, 2026, 6:08 p.m.

6.4

CVSS3.1

CVE-2025-14121 - EDD Download Info <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode A…

The EDD Download Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'edd_download_info_link' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat…

📅 Published: Jan. 7, 2026, 9:21 a.m. 🔄 Last Modified: Jan. 8, 2026, 6:08 p.m.

6.4

CVSS3.1

CVE-2025-14147 - Easy GitHub Gist Shortcodes <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via '…

The Easy GitHub Gist Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the gist shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi…

📅 Published: Jan. 7, 2026, 9:21 a.m. 🔄 Last Modified: Jan. 8, 2026, 6:08 p.m.

6.4

CVSS3.1

CVE-2025-13841 - Smart App Banners <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' and …

The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalign' parameters of the 'app-store-download' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attribute…

📅 Published: Jan. 7, 2026, 9:21 a.m. 🔄 Last Modified: Jan. 8, 2026, 6:08 p.m.

7.5

CVSS3.1

CVE-2025-13801 - Yoco Payments <= 3.8.8 - Unauthenticated Arbitrary File Read

The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.8.8 via the file parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

📅 Published: Jan. 7, 2026, 9:21 a.m. 🔄 Last Modified: Jan. 8, 2026, 6:08 p.m.
Total resulsts: 327160
Page 70 of 32,716
« previous page » next page
Filters