5.4
CVE-2025-32248 - WordPress SwiftXR (3D/AR/VR) Viewer plugin <= 1.0.7 - Cross Site Request Forgery (CSRF) vulnerabiliโฆ
Cross-Site Request Forgery (CSRF) vulnerability in SwiftXR SwiftXR (3D/AR/VR) Viewer swiftxr-3darvr-viewer allows Cross Site Request Forgery.This issue affects SwiftXR (3D/AR/VR) Viewer: from n/a through <= 1.0.7.
5.4
CVE-2025-32247 - WordPress AI Content Creator plugin <= 1.2.6 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in ABCdatos AI Content Creator ai-content-creator allows Cross Site Request Forgery.This issue affects AI Content Creator: from n/a through <= 1.2.6.
5.4
CVE-2025-32246 - WordPress 1-Click Backup & Restore Database plugin <= 1.0.3 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Tim Nguyen 1-Click Backup & Restore Database 1-click-backup-restore-database-by-sunbytes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 1-Click Backup & Restore Database: from n/a through <= 1.0.3.
6.5
CVE-2025-32241 - WordPress Official CleverReach WooCommerce Integration plugin <= 3.4.6 - CSRF to Settings Change vuโฆ
Cross-Site Request Forgery (CSRF) vulnerability in CleverReachยฎ Official CleverReach Plugin for WooCommerce cleverreach-wc allows Cross Site Request Forgery.This issue affects Official CleverReach Plugin for WooCommerce: from n/a through <= 3.4.6.
4.3
CVE-2025-32238 - WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Sensitive Dโฆ
Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Retrieve Embedded Sensitive Data.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/aโฆ
4.3
CVE-2025-32237 - WordPress MasterStudy LMS plugin <= 3.5.28 - Broken Access Control vulnerability
Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from n/a through <= 3.5.28.
4.3
CVE-2025-32235 - WordPress MP3 Audio Player โ Music Player, Podcast Player & Radio by Sonaar plugin <= 5.9.4 - Brokeโฆ
Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.9.4.
4.3
CVE-2025-32234 - WordPress AdMail plugin <= 1.7.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in aleswebs AdMail โ Multilingual Back in-Stock Notifier for WooCommerce admail allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AdMail โ Multilingual Back in-Stock Notifier for WooCommerce: from n/a through <= 1.7.0.
4.3
CVE-2025-32233 - WordPress Revive.so plugin <= 2.0.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in WP Chill Revive.so revive-so allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive.so: from n/a through <= 2.0.3.
4.3
CVE-2025-32232 - WordPress StaffList plugin <= 3.2.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in ERA404 StaffList stafflist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects StaffList: from n/a through <= 3.2.7.