6.5

CVSS3.1

CVE-2025-46482 - WordPress WP Quiz plugin <= 2.0.10 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Quiz wp-quiz allows Stored XSS.This issue affects WP Quiz: from n/a through <= 2.0.10.

πŸ“… Published: April 25, 2025, 7:52 a.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

5.3

CVSS3.1

CVE-2025-3743 - Upsell Funnel Builder for WooCommerce <= 3.0.0 - Unauthenticated Order Manipulation

The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the 'add_offer_in_cart' function.…

πŸ“… Published: April 25, 2025, 6:45 a.m. πŸ”„ Last Modified: April 20, 2026, 11:15 p.m.

8.8

CVSS3.1

CVE-2025-2238 - Vikinger <= 1.9.30 - Authenticated (Subscriber+) Privilege Escalation via 'vikinger_user_meta_updat…

The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restrictions in the 'vikinger_user_meta_update_ajax' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, …

πŸ“… Published: April 25, 2025, 6:45 a.m. πŸ”„ Last Modified: April 22, 2026, 1:45 a.m.

6.1

CVSS3.1

CVE-2025-3868 - Custom Admin-Bar Favorites <= 0.1 - Reflected Cross-Site Scripting

The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb…

πŸ“… Published: April 25, 2025, 6:45 a.m. πŸ”„ Last Modified: April 22, 2026, 1:45 a.m.

6.1

CVSS3.1

CVE-2025-3867 - Ajax Comment Form CST <= 1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation via the 'acform_cst_settings' page. This makes it possible for unauthenticated attackers to update settings and …

πŸ“… Published: April 25, 2025, 6:45 a.m. πŸ”„ Last Modified: April 22, 2026, 5:30 p.m.

6.1

CVSS3.1

CVE-2025-3866 - Add Google +1 (Plus one) social share Button <= 1.0.0 - Cross-Site Request Forgery to Stored Cross-…

The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the google-plus-one-share-button page. This makes it possible for unauthenticated at…

πŸ“… Published: April 25, 2025, 6:45 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-0671 - Email Subscribers < 5.7.50 - Admin+ Stored XSS in Template

The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: April 25, 2025, 6 a.m. πŸ”„ Last Modified: April 29, 2025, 9:20 p.m.

5.3

CVSS3.1

CVE-2025-3923 - Prevent Direct Access – Protect WordPress Files <= 2.8.8 - Unauthenticated Sensitive Information Ex…

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'generate_unique_string' due to insufficient randomness of the generated file name. This makes it possible for unauthenticated…

πŸ“… Published: April 25, 2025, 5:25 a.m. πŸ”„ Last Modified: April 20, 2026, 11:15 p.m.

5.4

CVSS3.1

CVE-2025-3861 - Prevent Direct Access 2.8.6 - 2.8.8.2 - Incorrect Authorization to Authenticated (Contributor+) Mul…

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability check on the 'pda_lite_custom_permission_check' function in versions 2.8.6 to 2.8.8.2. This makes it possible for authenticated a…

πŸ“… Published: April 25, 2025, 5:25 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-2580 - Contact Form by Bit Form <= 2.18.3 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Fi…

The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access a…

πŸ“… Published: April 25, 2025, 5:25 a.m. πŸ”„ Last Modified: April 22, 2026, 5:30 p.m.
Total resulsts: 349182
Page 5664 of 34,919
Β« previous page Β» next page
Filters