4.3
CVE-2025-47534 - WordPress Wordpress Auto Spinner plugin <= 3.25.0 - Broken Access Control Vulnerability
Missing Authorization vulnerability in ValvePress Wordpress Auto Spinner wp-auto-spinner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wordpress Auto Spinner: from n/a through <= 3.25.0.
5.4
CVE-2025-47556 - WordPress CSS3 Compare Pricing Tables for WordPress plugin <= 11.6 - Broken Access Control Vulnerabβ¦
Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through <= 11.6.
6.5
CVE-2025-47557 - WordPress MapSVG plugin <= 8.5.31 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG mapsvg allows Stored XSS.This issue affects MapSVG: from n/a through <= 8.5.31.
5
CVE-2025-47560 - WordPress MapSVG plugin < 8.6.13 - Broken Access Control Vulnerability
Missing Authorization vulnerability in RomanCode MapSVG mapsvg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MapSVG: from n/a through < 8.6.13.
5.3
CVE-2025-47562 - WordPress MapSVG plugin <= 8.5.34 - Content Injection Vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg allows Code Injection.This issue affects MapSVG: from n/a through <= 8.5.34.
5.3
CVE-2025-47563 - WordPress CURCY plugin <= 2.3.7 - Arbitrary Shortcode Execution vulnerability
Missing Authorization vulnerability in villatheme CURCY woocommerce-multi-currency allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CURCY: from n/a through <= 2.3.7.
5.3
CVE-2025-47564 - WordPress EventON plugin <= 4.9.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in ashanjay EventON eventon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects EventON: from n/a through <= 4.9.8.
7.6
CVE-2025-47567 - WordPress Video Player & FullScreen Video Background plugin <= 2.4.1 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Video Player & FullScreen Video Background universal-video-player-and-bg allows Blind SQL Injection.This issue affects Video Player & FullScreen Video Background: from n/a through <= 2β¦
7.5
CVE-2025-47693 - WordPress Fat Services Booking plugin <= 5.5 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Services Booking fat-services-booking allows PHP Local File Inclusion.This issue affects FAT Services Booking: from n/a through <= 5.5.
7.1
CVE-2025-48146 - WordPress SEO Flow by LupsOnline plugin <= 2.2.1 - CSRF to Stored XSS vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Michael Lups SEO Flow by LupsOnline lupsonline-link-netwerk allows Stored XSS.This issue affects SEO Flow by LupsOnline: from n/a through <= 2.2.1.