6.9

CVSS4.0

CVE-2025-2811 - GL.iNet GL-A1300 Slate Plus API redos

A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 …

📅 Published: April 26, 2025, 7 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-2907 - Order Delivery Date Pro for WooCommerce < 12.3.1 - Unauthenticated Arbitrary Option Update

The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. This leads to attackers being able to modify…

📅 Published: April 26, 2025, 6 a.m. 🔄 Last Modified: May 14, 2025, 7:52 p.m.

4.3

CVSS3.1

CVE-2025-3915 - Aeropage Sync for Airtable <= 3.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrar…

The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'aeropageDeletePost' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and abo…

📅 Published: April 26, 2025, 5:34 a.m. 🔄 Last Modified: April 20, 2026, 11:15 p.m.

8.8

CVSS3.1

CVE-2025-3906 - Integração entre Eduzz e Woocommerce 1.5.0 - 1.7.5 - Missing Authorization to Authenticated (Subscr…

The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wep_opcoes' function in all versions up to, and including, 1.7.5. This makes it possible for authenticated attackers, with Subscriber-level acce…

📅 Published: April 26, 2025, 5:34 a.m. 🔄 Last Modified: April 20, 2026, 11:15 p.m.

8.8

CVSS3.1

CVE-2025-3914 - Aeropage Sync for Airtable <= 3.2.0 - Authenticated (Subscriber+) Arbitrary File Upload

The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access a…

📅 Published: April 26, 2025, 5:34 a.m. 🔄 Last Modified: April 20, 2026, 11:15 p.m.

7.2

CVSS3.1

CVE-2025-3491 - Add custom page template <= 2.0.1 - Authenticated (Administrator+) PHP Code Injection to Remote Cod…

The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'acpt_validate_setting' function. This is due to insufficient sanitization of the 'template_name' parameter. This makes it possi…

📅 Published: April 26, 2025, 5:34 a.m. 🔄 Last Modified: April 21, 2026, 9:15 p.m.

6.4

CVSS3.1

CVE-2025-1458 - Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote A…

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like Dual Button, Creative Button, Image Stack and more in all versions up to, and including, 5.10.29 due to insuffici…

📅 Published: April 26, 2025, 5:34 a.m. 🔄 Last Modified: April 22, 2026, 8:15 a.m.

8.1

CVSS3.1

CVE-2025-2105 - Jupiter X Core <= 4.8.11 - Unauthenticated PHP Object Injection via PHAR

The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.11 via deserialization of untrusted input from the 'file' parameter of the 'raven_download_file' function. This makes it possible for attackers to inject a PHP Object through a PH…

📅 Published: April 26, 2025, 5:34 a.m. 🔄 Last Modified: April 21, 2026, 9:15 p.m.

8.8

CVSS3.1

CVE-2024-13808 - Xpro Elementor Addons - Pro <= 1.4.9 - Authenticated (Contributor+) Remote Code Execution

The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.9 via the custom PHP widget. This is due to their only being client side controls when determining who can access the widget. This makes it possible for authenticate…

📅 Published: April 26, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 4:34 p.m.

7.3

CVSS3.1

CVE-2025-2801 - Create custom forms for WordPress with a smart form plugin for smart businesses <= 1.2.4 - Unauthen…

The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.4. This is due to the software allowing users to execute an action that does not properly validate a …

📅 Published: April 26, 2025, 3:24 a.m. 🔄 Last Modified: April 20, 2026, 11:15 p.m.
Total resulsts: 349182
Page 5658 of 34,919
« previous page » next page
Filters