6.4

CVSS3.1

CVE-2025-3832 - FuseDesk <= 6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via successredirect Para…

The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access …

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 20, 2026, 11:15 p.m.

6.4

CVSS3.1

CVE-2025-2579 - Lottie Player <= 1.1.8 - Authenticated (Author+) Stored Cross-Site Scripting via File Upload

The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inj…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 21, 2026, 9:15 p.m.

8.8

CVSS3.1

CVE-2025-3607 - Frontend Login and Registration Blocks <= 1.0.8 - Authenticated (Subscriber+) Privilege Escalation …

The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.8. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it possible for authen…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 20, 2026, 11:15 p.m.

9.8

CVSS3.1

CVE-2025-3604 - Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for unauthenticated a…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 22, 2026, 1:45 a.m.

6.4

CVSS3.1

CVE-2025-2543 - Advanced Accordion Gutenberg Block <= 5.0.2 - Authenticated (Author+) Stored Cross-Site Scripting v…

The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 22, 2026, 1:45 a.m.

4.3

CVSS3.1

CVE-2025-1284 - Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) <= 4.1 - Insecure…

The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1 via the xc_woo_printer_preview AJAX action due to missing validation on a user controlled key. This …

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 21, 2026, 9:15 p.m.

8.8

CVSS3.1

CVE-2025-3101 - Configurator Theme Core <= 1.4.7 - Authenticated (Subscriber+) Privilege Escalation

The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.7. This is due to the plugin not properly validating user meta fields prior to updating them in the database. This makes it possible for authenticated attackers, with Sub…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 22, 2026, 1:45 a.m.

8.8

CVSS3.1

CVE-2025-3058 - Xelion Webchat <= 9.1.0 - Authenticated (Subscriber+) Arbitrary Options Update

The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the xwc_save_settings() function in all versions up to, and including, 9.1.0. This makes it possible for authenticated attackers, wit…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 22, 2026, 5:30 p.m.

9.1

CVSS3.1

CVE-2025-3065 - Database Toolset <= 1.8.4 - Unauthenticated Arbitrary File Deletion

The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code…

📅 Published: April 24, 2025, 8:23 a.m. 🔄 Last Modified: April 22, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2024-12244 - Missing Authorization in GitLab

An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.

📅 Published: April 24, 2025, 7:31 a.m. 🔄 Last Modified: Aug. 8, 2025, 4:54 p.m.
Total resulsts: 346534
Page 5417 of 34,654
« previous page » next page
Filters