4.3

CVSS3.1

CVE-2025-49284 - WordPress WP Maintenance Mode & Site Under Construction plugin <= 4.3 - Cross Site Request Forgery …

Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Maintenance Mode & Site Under Construction wp-maintenance-mode-site-under-construction allows Cross Site Request Forgery.This issue affects WP Maintenance Mode & Site Under Construction: from n/a through <= 4.3.

πŸ“… Published: June 6, 2025, 12:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

4.3

CVSS3.1

CVE-2025-49283 - WordPress Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant plugin <= 4.1.1 - …

Cross-Site Request Forgery (CSRF) vulnerability in Matthias Nordwig Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant gdpr-compliant-recaptcha-for-all-forms allows Cross Site Request Forgery.This issue affects Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-complia…

πŸ“… Published: June 6, 2025, 12:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

4.3

CVSS3.1

CVE-2025-49273 - WordPress WP Tools plugin <= 5.24 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in sminozzi WP Tools wptools allows Cross Site Request Forgery.This issue affects WP Tools: from n/a through <= 5.24.

πŸ“… Published: June 6, 2025, 12:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

4.3

CVSS3.1

CVE-2025-49272 - WordPress Trinity Audio plugin <= 5.20.0 - Broken Access Control Vulnerability

Missing Authorization vulnerability in sergiotrinity Trinity Audio trinity-audio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trinity Audio: from n/a through <= 5.20.0.

πŸ“… Published: June 6, 2025, 12:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

5.3

CVSS3.1

CVE-2025-49270 - WordPress WP-CRM System plugin <= 3.4.2 - Broken Access Control Vulnerability

Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP-CRM System: from n/a through <= 3.4.2.

πŸ“… Published: June 6, 2025, 12:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

4.3

CVSS3.1

CVE-2025-49269 - WordPress Market Exporter plugin <= 2.0.22 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Anton Vanyukov Market Exporter market-exporter allows Cross Site Request Forgery.This issue affects Market Exporter: from n/a through <= 2.0.22.

πŸ“… Published: June 6, 2025, 12:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

5.3

CVSS3.1

CVE-2025-49268 - WordPress Verge3D plugin <= 4.9.4 - Broken Access Control Vulnerability

Missing Authorization vulnerability in Soft8Soft LLC Verge3D verge3d allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Verge3D: from n/a through <= 4.9.4.

πŸ“… Published: June 6, 2025, 12:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

7.6

CVSS3.1

CVE-2025-49263 - WordPress WC Vendors Marketplace plugin <= 2.5.6 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WCVendors WC Vendors Marketplace wc-vendors allows Blind SQL Injection.This issue affects WC Vendors Marketplace: from n/a through <= 2.5.6.

πŸ“… Published: June 6, 2025, 12:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

7.6

CVSS3.1

CVE-2025-49262 - WordPress Sina Extension for Elementor plugin <= 3.6.1 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shaonsina Sina Extension for Elementor sina-extension-for-elementor allows Stored XSS.This issue affects Sina Extension for Elementor: from n/a through <= 3.6.1.

πŸ“… Published: June 6, 2025, 12:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

4.3

CVSS3.1

CVE-2025-49250 - WordPress Team Showcase plugin < 25.05.13 - Arbitrary Shortcode Execution vulnerability

Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase team-showcase-cm allows Code Injection.This issue affects Team Showcase: from n/a through < 25.05.13.

πŸ“… Published: June 6, 2025, 12:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.
Total resulsts: 348393
Page 5069 of 34,840
Β« previous page Β» next page
Filters