7.1

CVSS3.1

CVE-2025-28968 - WordPress WP Wall plugin <= 1.7.3 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac WP Wall allows Reflected XSS. This issue affects WP Wall: from n/a through 1.7.3.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

6.5

CVSS3.1

CVE-2025-28976 - WordPress Email Address Security by WebEmailProtector <= 3.3.6 - Cross Site Scripting (XSS) Vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dsrodzin Email Address Security by WebEmailProtector allows Stored XSS. This issue affects Email Address Security by WebEmailProtector: from n/a through 3.3.6.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

7.1

CVSS3.1

CVE-2025-28978 - WordPress SB Breadcrumbs plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hung Trang Si SB Breadcrumbs allows Reflected XSS. This issue affects SB Breadcrumbs: from n/a through 1.0.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

7.7

CVSS3.1

CVE-2025-28980 - WordPress Aviation Weather from NOAA <= 0.7.2 - Arbitrary File Deletion Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA allows Path Traversal. This issue affects Aviation Weather from NOAA: from n/a through 0.7.2.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

9.8

CVSS3.1

CVE-2025-28983 - WordPress Click & Pledge Connect plugin <= 25.04010101-WP6.8 - Privilege Escalation via SQL Injecti…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects Click & Pledge Connect: from 25.04010101 through WP6.8.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

10

CVSS3.1

CVE-2025-30933 - WordPress LogisticsHub <= 1.1.6 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub allows Upload a Web Shell to a Web Server. This issue affects LogisticsHub: from n/a through 1.1.6.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

7.1

CVSS3.1

CVE-2025-31037 - WordPress Homey theme <= 2.4.5 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey allows Reflected XSS. This issue affects Homey: from n/a through 2.4.5.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

8.5

CVSS3.1

CVE-2025-32297 - WordPress Simple Link Directory Pro plugin <= 14.7.3 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory allows SQL Injection. This issue affects Simple Link Directory: from n/a through 14.7.3.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

7.1

CVSS3.1

CVE-2025-32311 - WordPress Pressroom - News Magazine WordPress Theme theme <= 6.9 - Reflected Cross Site Scripting (…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Pressroom - News Magazine WordPress Theme allows Reflected XSS. This issue affects Pressroom - News Magazine WordPress Theme: from n/a through 6.9.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.

7.1

CVSS3.1

CVE-2025-39487 - WordPress Rankie plugin <= 1.8.2 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Rankie allows Reflected XSS. This issue affects Rankie: from n/a through 1.8.2.

πŸ“… Published: July 4, 2025, 11:18 a.m. πŸ”„ Last Modified: July 4, 2025, 12:15 p.m.
Total resulsts: 300467
Page 8 of 30,047
Β« previous page Β» next page
Filters