4.3

CVSS3.1

CVE-2025-69354 - WordPress Better Business Reviews plugin <= 0.1.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1.

๐Ÿ“… Published: Jan. 6, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:28 p.m.

4.3

CVSS3.1

CVE-2025-69353 - WordPress Proxy & VPN Blocker plugin <= 3.5.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Proxy &amp; VPN Blocker Proxy &amp; VPN Blocker proxy-vpn-blocker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Proxy &amp; VPN Blocker: from n/a through <= 3.5.3.

๐Ÿ“… Published: Jan. 6, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:28 p.m.

5.4

CVSS3.1

CVE-2025-69352 - WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.15.12.2.

๐Ÿ“… Published: Jan. 6, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:28 p.m.

8.5

CVSS3.1

CVE-2025-69351 - WordPress Ninja Tables plugin <= 5.2.4 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Blind SQL Injection.This issue affects Ninja Tables: from n/a through <= 5.2.4.

๐Ÿ“… Published: Jan. 6, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:28 p.m.

5.9

CVSS3.1

CVE-2025-69350 - WordPress Accordion plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accordion accordions-wp allows Stored XSS.This issue affects Accordion: from n/a through <= 3.0.3.

๐Ÿ“… Published: Jan. 6, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:28 p.m.

5.4

CVSS3.1

CVE-2025-69349 - WordPress RSS Feed Widget plugin <= 3.0.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RSS Feed Widget: from n/a through <= 3.0.2.

๐Ÿ“… Published: Jan. 6, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:28 p.m.

4.3

CVSS3.1

CVE-2025-69348 - WordPress The Events Calendar Countdown Addon plugin <= 1.4.15 - Broken Access Control vulnerability

Missing Authorization vulnerability in CoolHappy The Events Calendar Countdown Addon countdown-for-the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar Countdown Addon: from n/a through <= 1.4.15.

๐Ÿ“… Published: Jan. 6, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:28 p.m.

4.3

CVSS3.1

CVE-2025-69346 - WordPress AffiliateX plugin <= 1.3.9.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in WPCenter AffiliateX affiliatex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AffiliateX: from n/a through <= 1.3.9.3.

๐Ÿ“… Published: Jan. 6, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:28 p.m.

4.3

CVSS3.1

CVE-2025-69345 - WordPress Post and Page Builder by BoldGrid plugin <= 1.27.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.9.

๐Ÿ“… Published: Jan. 6, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:28 p.m.

7.5

CVSS3.1

CVE-2025-69342 - WordPress Calafate theme <= 1.7.7 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Calafate calafate allows PHP Local File Inclusion.This issue affects Calafate: from n/a through <= 1.7.7.

๐Ÿ“… Published: Jan. 6, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347725
Page 2123 of 34,773
ยซ previous page ยป next page
Filters