4.3

CVSS3.1

CVE-2025-13753 - WP Table Builder <= 2.0.19 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Table…

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect authorization check on the save_table() function in all versions up to, and including, 2.0.19. This makes it possible for authenticated attackers, with Subscr…

📅 Published: Jan. 9, 2026, 7:22 a.m. 🔄 Last Modified: April 20, 2026, 4 p.m.

4.3

CVSS3.1

CVE-2025-13935 - Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated …

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completion in all versions up to, and including, 3.9.2. This is due to missing enrollment verification in the 'mark_course_complete' function. This makes it possible for authenticated atta…

📅 Published: Jan. 9, 2026, 7:22 a.m. 🔄 Last Modified: April 22, 2026, 6:15 a.m.

4.3

CVSS3.1

CVE-2025-13934 - Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated …

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollment in all versions up to, and including, 3.9.3. This is due to a missing capability check and purchasability validation in the `course_enrollment()` AJAX handler. This makes it pos…

📅 Published: Jan. 9, 2026, 7:22 a.m. 🔄 Last Modified: April 22, 2026, 4 a.m.

9.1

CVSS3.1

CVE-2025-14741 - Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data D…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenticated att…

📅 Published: Jan. 9, 2026, 7:22 a.m. 🔄 Last Modified: April 22, 2026, 12:15 a.m.

4.3

CVSS3.1

CVE-2025-13628 - Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated …

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability check on the 'bulk_action_handler' and 'coupon_permanent_delete' functions in all versions up to, and including, 3.9.3. This makes it…

📅 Published: Jan. 9, 2026, 7:22 a.m. 🔄 Last Modified: April 21, 2026, 4:45 p.m.

7.2

CVSS3.1

CVE-2025-14937 - Frontend Admin by DynamiApps <= 3.28.23 - Unauthenticated Stored Cross-Site Scripting via 'update_f…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/forms/update_field' AJAX action in all versions up to, and including, 3.28.23 due to insufficient input sanitization and output escaping. This makes it …

📅 Published: Jan. 9, 2026, 7:22 a.m. 🔄 Last Modified: April 22, 2026, 12:15 a.m.

5.3

CVSS3.1

CVE-2025-14146 - Booking Calendar <= 10.14.10 - Unauthenticated Sensitive Information Exposure

The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPBC_FLEXTIMELINE_NAV` AJAX action. This is due to the nonce verification being conditionally disabled by default (`booking_is_nonce_at_front_end` option…

📅 Published: Jan. 9, 2026, 7:22 a.m. 🔄 Last Modified: April 22, 2026, 3:45 p.m.

8.2

CVSS4.0

CVE-2026-21409 - Improper Authorization Allows Retrieval of User Registration Information and OIDC Tokens via Man‑in…

Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID …

📅 Published: Jan. 9, 2026, 7:15 a.m. 🔄 Last Modified: April 18, 2026, 7:30 a.m.

10

CVSS3.1

CVE-2025-70974 - fastjson: From CVEorg collector

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-su…

📅 Published: Jan. 9, 2026, 6:43 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-14574 - weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.1.15 - Unauthenticat…

The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.15 via the `/wp-json/wp/v2/docs/settings` REST API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including third party services API ke…

📅 Published: Jan. 9, 2026, 6:34 a.m. 🔄 Last Modified: April 20, 2026, 9:15 p.m.
Total resulsts: 346506
Page 1947 of 34,651
« previous page » next page
Filters