9.8

CVSS3.1

CVE-2025-23970 - WordPress Service Finder Booking <= 6.0 - Privilege Escalation Vulnerability

Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking allows Privilege Escalation. This issue affects Service Finder Booking: from n/a through 6.0.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

7.1

CVSS3.1

CVE-2025-24771 - WordPress Content Manager Light plugin <= 3.2 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content Manager Light allows Reflected XSS. This issue affects Content Manager Light: from n/a through 3.2.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

8.5

CVSS3.1

CVE-2025-24780 - WordPress Printcart Web to Print Product Designer for WooCommerce <= 2.4.0 - SQL Injection Vulnerab…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce allows SQL Injection. This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through 2.4.0.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

7.1

CVSS3.1

CVE-2025-28968 - WordPress WP Wall plugin <= 1.7.3 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac WP Wall allows Reflected XSS. This issue affects WP Wall: from n/a through 1.7.3.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

6.5

CVSS3.1

CVE-2025-28976 - WordPress Email Address Security by WebEmailProtector <= 3.3.6 - Cross Site Scripting (XSS) Vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dsrodzin Email Address Security by WebEmailProtector allows Stored XSS. This issue affects Email Address Security by WebEmailProtector: from n/a through 3.3.6.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

7.1

CVSS3.1

CVE-2025-28978 - WordPress SB Breadcrumbs plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hung Trang Si SB Breadcrumbs allows Reflected XSS. This issue affects SB Breadcrumbs: from n/a through 1.0.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

7.7

CVSS3.1

CVE-2025-28980 - WordPress Aviation Weather from NOAA <= 0.7.2 - Arbitrary File Deletion Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA allows Path Traversal. This issue affects Aviation Weather from NOAA: from n/a through 0.7.2.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

9.8

CVSS3.1

CVE-2025-28983 - WordPress Click & Pledge Connect plugin <= 25.04010101-WP6.8 - Privilege Escalation via SQL Injecti…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects Click & Pledge Connect: from 25.04010101 through WP6.8.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

10

CVSS3.1

CVE-2025-30933 - WordPress LogisticsHub <= 1.1.6 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub allows Upload a Web Shell to a Web Server. This issue affects LogisticsHub: from n/a through 1.1.6.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

7.1

CVSS3.1

CVE-2025-31037 - WordPress Homey theme <= 2.4.5 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey allows Reflected XSS. This issue affects Homey: from n/a through 2.4.5.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.
Total resulsts: 300452
Page 8 of 30,046
Β« previous page Β» next page
Filters