4.3

CVSS3.1

CVE-2025-32261 - WordPress Advanced All in One Admin Search by WP Spotlight plugin <= 1.1.1 - Cross Site Request For…

Cross-Site Request Forgery (CSRF) vulnerability in Kuppuraj Advanced All in One Admin Search by WP Spotlight wp-spotlight-search allows Cross Site Request Forgery.This issue affects Advanced All in One Admin Search by WP Spotlight: from n/a through <= 1.1.1.

πŸ“… Published: April 4, 2025, 3:59 p.m. πŸ”„ Last Modified: April 23, 2026, 3:28 p.m.

5.3

CVSS3.1

CVE-2025-32258 - WordPress Simple Website Logo plugin <= 1.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in InfoGiants Simple Website Logo simple-website-logo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Website Logo: from n/a through <= 1.1.

πŸ“… Published: April 4, 2025, 3:59 p.m. πŸ”„ Last Modified: April 23, 2026, 3:28 p.m.

5.3

CVSS3.1

CVE-2025-32257 - WordPress 1 Click WordPress Migration plugin <= 2.5.7 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Click WordPress Migration: from n/a through <= 2.5.7.

πŸ“… Published: April 4, 2025, 3:59 p.m. πŸ”„ Last Modified: April 28, 2026, 4:12 p.m.

5.3

CVSS3.1

CVE-2025-32256 - WordPress SurveyJS plugin <= 1.12.20 - Broken Access Control vulnerability

Missing Authorization vulnerability in devsoftbaltic SurveyJS surveyjs allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SurveyJS: from n/a through <= 1.12.20.

πŸ“… Published: April 4, 2025, 3:59 p.m. πŸ”„ Last Modified: April 23, 2026, 3:28 p.m.

5.3

CVSS3.1

CVE-2025-32255 - WordPress StaffList plugin <= 3.2.7 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ERA404 StaffList stafflist allows Retrieve Embedded Sensitive Data.This issue affects StaffList: from n/a through <= 3.2.7.

πŸ“… Published: April 4, 2025, 3:59 p.m. πŸ”„ Last Modified: April 23, 2026, 3:28 p.m.

5.3

CVSS3.1

CVE-2025-32254 - WordPress WPBookit plugin <= 1.0.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPBookit: from n/a through <= 1.0.7.

πŸ“… Published: April 4, 2025, 3:59 p.m. πŸ”„ Last Modified: April 23, 2026, 3:28 p.m.

5.3

CVSS3.1

CVE-2025-32253 - WordPress Course Booking System Plugin <= 6.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in ComMotion Course Booking System course-booking-system allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Course Booking System: from n/a through <= 6.1.

πŸ“… Published: April 4, 2025, 3:59 p.m. πŸ”„ Last Modified: April 23, 2026, 3:28 p.m.

5.3

CVSS3.1

CVE-2025-32252 - WordPress WP Genealogy plugin <= 0.1.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in Black and White WP Genealogy – Your Family History Website wpgenealogy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Genealogy – Your Family History Website: from n/a through <= 0.1.9.

πŸ“… Published: April 4, 2025, 3:59 p.m. πŸ”„ Last Modified: April 23, 2026, 3:28 p.m.

5.3

CVSS3.1

CVE-2025-32251 - WordPress Jetpack Feedback Exporter plugin <= 1.23 - Sensitive Data Exposure Vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J. Tyler Wiest Jetpack Feedback Exporter jetpack-feedback-exporter allows Retrieve Embedded Sensitive Data.This issue affects Jetpack Feedback Exporter: from n/a through <= 1.23.

πŸ“… Published: April 4, 2025, 3:59 p.m. πŸ”„ Last Modified: April 23, 2026, 3:28 p.m.

5.4

CVSS3.1

CVE-2025-32249 - WordPress DirectoryPress Plugin <= 3.6.22 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Designinvento DirectoryPress directorypress allows Cross Site Request Forgery.This issue affects DirectoryPress: from n/a through <= 3.6.22.

πŸ“… Published: April 4, 2025, 3:59 p.m. πŸ”„ Last Modified: April 23, 2026, 3:28 p.m.
Total resulsts: 349182
Page 6008 of 34,919
Β« previous page Β» next page
Filters