4.3

CVSS3.1

CVE-2025-0515 - Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme <= 2.0.4 - Missing Authorizatio…

The Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cmsmasters_hide_admin_notice' function in all versions up to, and including, …

📅 Published: Jan. 18, 2025, 7:05 a.m. 🔄 Last Modified: April 22, 2026, 1:45 p.m.

6.1

CVSS3.1

CVE-2024-13432 - Webcamconsult <= 1.5.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web script…

📅 Published: Jan. 18, 2025, 7:05 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-13391 - MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet <= 2.9.29 -…

The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_content_upload_guest' shortcode in all versions up to, and including, 2.9.29 due to insufficient input sanitiz…

📅 Published: Jan. 18, 2025, 7:05 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-9020 - List category posts < 0.90.3 - Author+ Stored XSS

The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

📅 Published: Jan. 18, 2025, 6 a.m. 🔄 Last Modified: May 13, 2025, 9:23 p.m.

7.5

CVSS3.1

CVE-2025-0308 - Ultimate Member <= 2.9.1 - Unauthenticated SQL Injection

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied pa…

📅 Published: Jan. 18, 2025, 5:33 a.m. 🔄 Last Modified: April 22, 2026, 7:15 a.m.

6.1

CVSS3.1

CVE-2024-13516 - Kubio AI Page Builder <= 2.3.5 - Reflected Cross-Site Scripting

The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

📅 Published: Jan. 18, 2025, 5:33 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-13515 - Image Source Control Lite – Show Image Credits and Captions <= 2.28.0 - Reflected Cross-Site Script…

The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'path' parameter in all versions up to, and including, 2.28.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthent…

📅 Published: Jan. 18, 2025, 5:33 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-0318 - Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Member…

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for una…

📅 Published: Jan. 18, 2025, 5:33 a.m. 🔄 Last Modified: April 22, 2026, 1:45 p.m.

4.4

CVSS3.1

CVE-2025-0554 - Podlove Podcast Publisher <= 4.1.25 - Authenticated (Admin+) Stored Cross-Site Scripting via Feed N…

The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Feed Name value in version <= 4.1.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arb…

📅 Published: Jan. 18, 2025, 5:33 a.m. 🔄 Last Modified: April 22, 2026, 1:45 p.m.

5.3

CVSS3.1

CVE-2024-12071 - Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media <= 1.4.4 - Miss…

The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_network_post() function in all versions up to, and including, 1.4.4. This makes it possible for una…

📅 Published: Jan. 18, 2025, 3:21 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.
Total resulsts: 349182
Page 7054 of 34,919
« previous page » next page
Filters