4.3

CVSS3.1

CVE-2023-47232 - WordPress WP Affiliate Disclosure plugin <= 1.2.6 - Broken Access Control + CSRF vulnerability

Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: from n/a through 1.2.6.

๐Ÿ“… Published: Dec. 21, 2025, 12:06 a.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

7.7

CVSS3.1

CVE-2023-25446 - WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1.

๐Ÿ“… Published: Dec. 21, 2025, 12:01 a.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

5.4

CVSS3.1

CVE-2023-25445 - WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in HappyFiles HappyFiles Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1.

๐Ÿ“… Published: Dec. 21, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

4.3

CVSS3.1

CVE-2023-25068 - WordPress Magazine Edge theme <= 1.13 - Authenticated Arbitrary Plugin Activation

Missing Authorization vulnerability in Mapro Collins Magazine Edge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Edge: from n/a through 1.13.

๐Ÿ“… Published: Dec. 20, 2025, 11:58 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

6.9

CVSS4.0

CVE-2025-14989 - Campcodes Complete Online Beauty Parlor Management System search-invoices.php sql injection

A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the file /admin/search-invoices.php. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit is publicly available and miโ€ฆ

๐Ÿ“… Published: Dec. 20, 2025, 11:32 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

8.5

CVSS4.0

CVE-2025-34290 - Versa SASE Client for Windows < 7.9.5 Arbitrary Folder Deletion Leading to Local Privilege Escalatiโ€ฆ

Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating tโ€ฆ

๐Ÿ“… Published: Dec. 20, 2025, 8:01 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

7.6

CVSS3.1

CVE-2025-7782 - WP JobHunt <= 7.7 - Missing Authorization to Authenticated (Candidate+) Stored Cross-Site Scriptingโ€ฆ

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due to a missing capability check on the 'cs_update_application_status_callback' function in all versions up to, and including, 7.7. This makes it possible for authenticated attackerโ€ฆ

๐Ÿ“… Published: Dec. 20, 2025, 1:47 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

4.3

CVSS3.1

CVE-2025-7733 - WP JobHunt <= 7.7 - Authenticated (Candidate+) Insecure Direct Object Reference

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.7 via the 'cs_update_application_status_callback' due to missing validation on a user controlled key. This makes it possible for authenticated โ€ฆ

๐Ÿ“… Published: Dec. 20, 2025, 1:47 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

5.4

CVSS3.1

CVE-2025-14298 - FiboSearch โ€“ Ajax Search for WooCommerce <= 1.32.0 - Authenticated (Contributor+) Stored Cross-Siteโ€ฆ

The FiboSearch โ€“ Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up to, and including, 1.32.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makeโ€ฆ

๐Ÿ“… Published: Dec. 20, 2025, 8:22 a.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

5.3

CVSS3.1

CVE-2025-12492 - Ultimate Member โ€“ User Profile, Registration, Login, Member Directory, Content Restriction & Memberโ€ฆ

The Ultimate Member โ€“ User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to the use of a predictโ€ฆ

๐Ÿ“… Published: Dec. 20, 2025, 8:22 a.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.
Total resulsts: 324275
Page 75 of 32,428
ยซ previous page ยป next page
Filters