CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2025-68526

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows Object Injection.This issue affects Modal Popup Box: from n/a through <= 1.6.1.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68514

    Last Modified: 29 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.16.8.

    Published: 20 Feb 2026
    7.1
    High

    CVE-2025-68501

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce allows Reflected XSS.This issue affects Mollie Payments for WooCommerce: from n/a through <= 8.1.1.

    Published: 20 Feb 2026
    7.1
    High

    CVE-2025-68495

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0.

    Published: 20 Feb 2026
    7.1
    High

    CVE-2025-68069

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.6.6.

    Published: 20 Feb 2026
    7.5
    High

    CVE-2025-68051

    Last Modified: 27 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Shiprocket Shiprocket shiprocket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shiprocket: from n/a through <= 2.0.8.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68050

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Leadpages Leadpages leadpages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leadpages: from n/a through <= 1.1.3.

    Published: 20 Feb 2026
    7.5
    High

    CVE-2025-68048

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NextMove Lite: from n/a through <= 2.23.0.

    Published: 20 Feb 2026
    7.3
    High

    CVE-2025-68043

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in LottieFiles LottieFiles lottiefiles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LottieFiles: from n/a through <= 3.0.0.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68042

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Travelpayouts Travelpayouts travelpayouts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travelpayouts: from n/a through <= 1.2.2.

    Published: 20 Feb 2026
    7.1
    High

    CVE-2025-68037

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atlas Gondal Export Media URLs export-media-urls allows Reflected XSS.This issue affects Export Media URLs: from n/a through <= 2.2.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68032

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Passionate Brains Advanced WC Analytics advance-wc-analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced WC Analytics: from n/a through <= 3.19.0.

    Published: 20 Feb 2026
    7.1
    High

    CVE-2025-68031

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faraz sms افزونه پیامک حرفه ای فراز اس ام اس farazsms allows Reflected XSS.This issue affects افزونه پیامک حرفه ای فراز اس ام اس: from n/a through <= 2.7.3.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68028

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GA4WP: Google Analytics for WordPress: from n/a through <= 2.10.0.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68026

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Niaj Morshed LC Wizard ghl-wizard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LC Wizard: from n/a through <= 2.1.1.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68025

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Addonify Addonify Floating Cart For WooCommerce addonify-floating-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify Floating Cart For WooCommerce: from n/a through <= 1.2.17.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68024

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Addonify Addonify – WooCommerce Wishlist addonify-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify – WooCommerce Wishlist: from n/a through <= 2.0.15.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68023

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Addonify Addonify – Compare Products For WooCommerce addonify-compare-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify – Compare Products For WooCommerce: from n/a through <= 1.1.17.

    Published: 20 Feb 2026
    7.3
    High

    CVE-2025-68022

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in soporteblue Plugin BlueX for WooCommerce bluex-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Plugin BlueX for WooCommerce: from n/a through <= 3.1.6.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68021

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ConveyThis: from n/a through <= 269.9.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68005

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in themewant Easy Hotel Booking easy-hotel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Hotel Booking: from n/a through <= 1.9.2.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68002

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 100plugins Open User Map open-user-map allows Path Traversal.This issue affects Open User Map: from n/a through <= 1.4.16.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-68000

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonial Slider: from n/a through <= 2.0.15.

    Published: 20 Feb 2026
    8.8
    High

    CVE-2025-67998

    Last Modified: 15 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in kamleshyadav Miraculous Elementor miraculous-el allows Authentication Abuse.This issue affects Miraculous Elementor: from n/a through <= 2.0.7.

    Published: 20 Feb 2026
    9.8
    Critical

    CVE-2025-67997

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This issue affects Travelicious: from n/a through < 1.6.7.

    Published: 20 Feb 2026
    9.8
    Critical

    CVE-2025-67996

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects Nestin: from n/a through < 1.2.6.

    Published: 20 Feb 2026
    9.8
    Critical

    CVE-2025-67995

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affects PatioTime: from n/a through < 2.1.

    Published: 20 Feb 2026
    7.5
    High

    CVE-2025-67994

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in YayCommerce YayCurrency yaycurrency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayCurrency: from n/a through <= 3.3.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-67993

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.2.1.

    Published: 20 Feb 2026
    8.1
    High

    CVE-2025-67992

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean PatioTime patiotime allows PHP Local File Inclusion.This issue affects PatioTime: from n/a through < 2.1.

    Published: 20 Feb 2026
    7.1
    High

    CVE-2025-67991

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Reflected XSS.This issue affects User Extra Fields: from n/a through <= 16.8.

    Published: 20 Feb 2026
    7.1
    High

    CVE-2025-67990

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 GMap Targeting gmap-targeting allows Reflected XSS.This issue affects GMap Targeting: from n/a through <= 1.1.7.

    Published: 20 Feb 2026
    8.1
    High

    CVE-2025-67988

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean CozyStay cozystay allows PHP Local File Inclusion.This issue affects CozyStay: from n/a through < 1.9.1.

    Published: 20 Feb 2026
    8.5
    High

    CVE-2025-67987

    Last Modified: 15 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows SQL Injection.This issue affects Quiz And Survey Master: from n/a through <= 10.3.1.

    Published: 20 Feb 2026
    7.1
    High

    CVE-2025-67984

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in calliko NPS computy nps-computy allows DOM-Based XSS.This issue affects NPS computy: from n/a through <= 2.8.2.

    Published: 20 Feb 2026
    8.1
    High

    CVE-2025-67982

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local File Inclusion.This issue affects Urna: from n/a through <= 2.5.12.

    Published: 20 Feb 2026
    8.1
    High

    CVE-2025-67981

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local File Inclusion.This issue affects Besa: from n/a through <= 2.3.15.

    Published: 20 Feb 2026
    8.1
    High

    CVE-2025-67980

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Hara hara allows PHP Local File Inclusion.This issue affects Hara: from n/a through <= 1.2.17.

    Published: 20 Feb 2026
    9.9
    Critical

    CVE-2025-67979

    Last Modified: 15 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gsheetconnector-wpforms allows Code Injection.This issue affects WPForms Google Sheet Connector: from n/a through <= 4.0.1.

    Published: 20 Feb 2026
    7.1
    High

    CVE-2025-67978

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FixBD Educare educare allows Reflected XSS.This issue affects Educare: from n/a through <= 1.6.1.

    Published: 20 Feb 2026
    8.2
    High

    CVE-2025-67977

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.8.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-67975

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in aDirectory aDirectory adirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects aDirectory: from n/a through <= 3.0.3.

    Published: 20 Feb 2026
    7.5
    High

    CVE-2025-67974

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in WP Legal Pages WPLegalPages wplegalpages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLegalPages: from n/a through <= 3.5.4.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-67973

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.6.2.

    Published: 20 Feb 2026
    4.3
    Medium

    CVE-2025-67972

    Last Modified: 21 May 2026

    Missing Authorization vulnerability in Zoho Mail Zoho ZeptoMail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zoho ZeptoMail: from n/a through 3.2.9.

    Published: 20 Feb 2026
    7.1
    High

    CVE-2025-67971

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja FluentCart fluent-cart allows Reflected XSS.This issue affects FluentCart: from n/a through < 1.3.0.

    Published: 20 Feb 2026
    5.9
    Medium

    CVE-2025-67970

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in vertim Schedula schedula-smart-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schedula: from n/a through <= 1.0.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-67969

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in knitpay UPI QR Code Payment Gateway for WooCommerce upi-qr-code-payment-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UPI QR Code Payment Gateway for WooCommerce: from n/a through <= 1.5.1.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-67624

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Arya Dhiratara Optimize More! – Images optimize-more-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Optimize More! – Images: from n/a through <= 1.1.3.

    Published: 20 Feb 2026
    6.5
    Medium

    CVE-2025-67547

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in uixthemes Konte konte allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Konte: from n/a through <= 2.4.6.

    Published: 20 Feb 2026