5.3

CVSS4.0

CVE-2025-13546 - ashraf-kabir travel-agency Search results.php sql injection

A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this issue is some unknown functionality of the file /results.php of the component Search. The manipulation of the argument user_query results in sql injection. The attack can be l…

📅 Published: Nov. 23, 2025, 10:32 a.m. 🔄 Last Modified: Nov. 23, 2025, 10:32 a.m.

5.1

CVSS4.0

CVE-2025-13545 - ashraf-kabir travel-agency index.php sql injection

A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this vulnerability is an unknown functionality of the file /admin_area/index.php. The manipulation of the argument edit_pack leads to sql injection. The attack can be…

📅 Published: Nov. 23, 2025, 10:02 a.m. 🔄 Last Modified: Nov. 23, 2025, 10:02 a.m.

5.3

CVSS4.0

CVE-2025-13544 - ashraf-kabir travel-agency customer_register.php unrestricted upload

A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been…

📅 Published: Nov. 23, 2025, 9:02 a.m. 🔄 Last Modified: Nov. 23, 2025, 9:02 a.m.

7.5

CVSS3.1

CVE-2025-13526 - OneClick Chat to Order <= 1.0.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Inf…

The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.8 via the 'wa_order_thank_you_override' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to vi…

📅 Published: Nov. 22, 2025, 11:08 a.m. 🔄 Last Modified: Nov. 22, 2025, 11:08 a.m.

5.3

CVSS3.1

CVE-2025-13318 - Booking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Bookin…

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthentica…

📅 Published: Nov. 22, 2025, 8:30 a.m. 🔄 Last Modified: Nov. 22, 2025, 8:30 a.m.

4.3

CVSS3.1

CVE-2025-13136 - GSheetConnector For Ninja Forms <= 2.0.1 - Missing Authorization to Authenticated (Subscriber+) Sys…

The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'njform-google-sheet-config ' page in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with Subscriber-level ac…

📅 Published: Nov. 22, 2025, 8:30 a.m. 🔄 Last Modified: Nov. 22, 2025, 8:30 a.m.

5.3

CVSS3.1

CVE-2025-12877 - IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to …

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability check on the panding_blood_request_action() function in all versions up to, and including, 2.1.15. This makes it possible for unauthe…

📅 Published: Nov. 22, 2025, 7:29 a.m. 🔄 Last Modified: Nov. 22, 2025, 7:29 a.m.

5.3

CVSS3.1

CVE-2025-12752 - Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creation

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fak…

📅 Published: Nov. 22, 2025, 7:29 a.m. 🔄 Last Modified: Nov. 22, 2025, 7:29 a.m.

7.5

CVSS3.1

CVE-2025-13384 - CP Contact Form with PayPal <= 1.3.56 - Missing Authorization to Unauthenticated Arbitrary Payment …

The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.56. This is due to the plugin exposing an unauthenticated IPN-like endpoint (via the 'cp_contactformpp_ipncheck' query parameter) that processes payment confirmation…

📅 Published: Nov. 22, 2025, 7:29 a.m. 🔄 Last Modified: Nov. 22, 2025, 7:29 a.m.

5.3

CVSS3.1

CVE-2025-13317 - Appointment Booking Calendar <= 1.3.96 - Missing Authorization to Arbitrary Booking Confirmation vi…

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the plugin exposing an unauthenticated booking processing endpoint (cpabc_appointments_check_IPN_verification) that trusts attacker-supplied paym…

📅 Published: Nov. 22, 2025, 7:29 a.m. 🔄 Last Modified: Nov. 22, 2025, 7:29 a.m.
Total resulsts: 319139
Page 1 of 31,914
» next page
Filters