5.3
CVE-2025-3281 - User Registration & Membership โ Custom Registration Form, Login Form, and User Profile <= 4.2.1 - โฆ
The User Registration & Membership โ Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation on the 'member_id' โฆ
5.1
CVE-2025-46593 -
Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.
4.4
CVE-2025-46592 -
Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availability.
6.2
CVE-2025-46591 -
Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
6.3
CVE-2025-46590 -
Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authentication and enable access to some network search functions.
4.4
CVE-2025-46589 -
Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
4.4
CVE-2025-46588 -
Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
6.2
CVE-2024-58252 -
Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
6.2
CVE-2025-46587 -
Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
5.1
CVE-2025-46586 -
Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.