4.3

CVSS3.1

CVE-2025-14354 - Resource Library for Logged In Users <= 1.4 - Cross-Site Request Forgery to Multiple Administrative…

The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various …

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:20 a.m.

4.3

CVSS3.1

CVE-2025-14165 - Kirim.Email WooCommerce Integration <= 1.2.9 - Cross-Site Request Forgery to Settings Update

The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9. This is due to missing nonce validation on the plugin's settings page. This makes it possible for unauthenticated attackers to modify the plugin's AP…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:20 a.m.

6.4

CVSS3.1

CVE-2025-13846 - Easy Map Creator <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode …

The Easy Map Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access …

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:20 a.m.

4.3

CVSS3.1

CVE-2025-13363 - IMAQ Core <= 1.2.1 - Cross-Site Request Forgery to URL Structure Update

The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the URL structure settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's URL str…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:20 a.m.

4.3

CVSS3.1

CVE-2025-12783 - Premmerce Brands for WooCommerce <= 1.2.13 - Missing Authorization To Authenticated (Subscriber+) B…

The Premmerce Brands for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveBrandsSettings function in all versions up to, and including, 1.2.13. This makes it possible for authenticated attackers, with Subscriber-level a…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:20 a.m.

8.1

CVSS3.1

CVE-2025-14044 - Visitor Logic Lite <= 1.0.3 - Unauthenticated PHP Object Injection via 'lpblocks' Cookie

The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.3 via deserialization of untrusted input from the `lpblocks` cookie. This is due to the `lp_track()` function passing unsanitized cookie data directly to the `unserialize()` f…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:20 a.m.

5.3

CVSS3.1

CVE-2025-14166 - WPMasterToolKit (WPMTK) <= 2.13.0 - Authenticated (Contributor+) Code Injection

The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13.0. This is due to the plugin allowing Author-level users to create and execute arbitrary PHP code through the Code Snippets feature without proper capability checks. This makes it…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:20 a.m.

6.4

CVSS3.1

CVE-2025-14119 - App Landing Template Blocks for WPBakery Page Builder <= 2.0.2 - Authenticated (Contributor+) Store…

The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'atvc_video_play' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied a…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:20 a.m.

4.3

CVSS3.1

CVE-2025-14158 - Coding Blocks <= 1.1.0 - Cross-Site Request Forgery to Settings Update

The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update plugin settings including the …

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:20 a.m.

6.4

CVSS3.1

CVE-2025-13904 - WPGancio <= 1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The WPGancio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gancio-event' shortcode in all versions up to, and including, 1.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack…

πŸ“… Published: Dec. 12, 2025, 3:20 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:20 a.m.
Total resulsts: 322002
Page 8 of 32,201
Β« previous page Β» next page
Filters