4.3
CVE-2023-47232 - WordPress WP Affiliate Disclosure plugin <= 1.2.6 - Broken Access Control + CSRF vulnerability
Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: from n/a through 1.2.6.
7.7
CVE-2023-25446 - WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1.
5.4
CVE-2023-25445 - WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in HappyFiles HappyFiles Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1.
4.3
CVE-2023-25068 - WordPress Magazine Edge theme <= 1.13 - Authenticated Arbitrary Plugin Activation
Missing Authorization vulnerability in Mapro Collins Magazine Edge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Edge: from n/a through 1.13.
6.9
CVE-2025-14989 - Campcodes Complete Online Beauty Parlor Management System search-invoices.php sql injection
A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the file /admin/search-invoices.php. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit is publicly available and miโฆ
8.5
CVE-2025-34290 - Versa SASE Client for Windows < 7.9.5 Arbitrary Folder Deletion Leading to Local Privilege Escalatiโฆ
Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating tโฆ
7.6
CVE-2025-7782 - WP JobHunt <= 7.7 - Missing Authorization to Authenticated (Candidate+) Stored Cross-Site Scriptingโฆ
The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due to a missing capability check on the 'cs_update_application_status_callback' function in all versions up to, and including, 7.7. This makes it possible for authenticated attackerโฆ
4.3
CVE-2025-7733 - WP JobHunt <= 7.7 - Authenticated (Candidate+) Insecure Direct Object Reference
The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.7 via the 'cs_update_application_status_callback' due to missing validation on a user controlled key. This makes it possible for authenticated โฆ
5.4
CVE-2025-14298 - FiboSearch โ Ajax Search for WooCommerce <= 1.32.0 - Authenticated (Contributor+) Stored Cross-Siteโฆ
The FiboSearch โ Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up to, and including, 1.32.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makeโฆ
5.3
CVE-2025-12492 - Ultimate Member โ User Profile, Registration, Login, Member Directory, Content Restriction & Memberโฆ
The Ultimate Member โ User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to the use of a predictโฆ