CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2025-67955

    Last Modified: 27 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP MyHome Core myhome-core allows PHP Local File Inclusion.This issue affects MyHome Core: from n/a through <= 4.1.0.

    Published: 22 Jan 2026
    6.5
    Medium

    CVE-2025-67954

    Last Modified: 15 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Retrieve Embedded Sensitive Data.This issue affects Salon booking system: from n/a through <= 10.30.3.

    Published: 22 Jan 2026
    8.1
    High

    CVE-2025-67953

    Last Modified: 15 Apr 2026

    Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue affects Booking Activities: from n/a through <= 1.16.44.

    Published: 22 Jan 2026
    7.1
    High

    CVE-2025-67952

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Tour grandtour allows Reflected XSS.This issue affects Grand Tour: from n/a through < 5.6.2.

    Published: 22 Jan 2026
    7.1
    High

    CVE-2025-67949

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designingmedia Hostiko hostiko allows Reflected XSS.This issue affects Hostiko: from n/a through < 94.3.6.

    Published: 22 Jan 2026
    7.1
    High

    CVE-2025-67947

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle AdForest Elementor adforest-elementor allows Reflected XSS.This issue affects AdForest Elementor: from n/a through <= 3.0.11.

    Published: 22 Jan 2026
    8.1
    High

    CVE-2025-67946

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in scriptsbundle AdForest adforest allows PHP Local File Inclusion.This issue affects AdForest: from n/a through <= 6.0.11.

    Published: 22 Jan 2026
    9.3
    Critical

    CVE-2025-67945

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite – WooCommerce integration woo-mailerlite allows SQL Injection.This issue affects MailerLite – WooCommerce integration: from n/a through <= 3.1.2.

    Published: 22 Jan 2026
    9.1
    Critical

    CVE-2025-67944

    Last Modified: 27 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.1.8.

    Published: 22 Jan 2026
    7.1
    High

    CVE-2025-67943

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Reflected XSS.This issue affects My auctions allegro: from n/a through <= 3.6.32.

    Published: 22 Jan 2026
    6.5
    Medium

    CVE-2025-67942

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 3.3.6.

    Published: 22 Jan 2026
    8.1
    High

    CVE-2025-67941

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes The Aisle theaisle allows PHP Local File Inclusion.This issue affects The Aisle: from n/a through < 2.9.1.

    Published: 22 Jan 2026
    8.1
    High

    CVE-2025-67940

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Powerlift powerlift allows PHP Local File Inclusion.This issue affects Powerlift: from n/a through < 3.2.1.

    Published: 22 Jan 2026
    6.5
    Medium

    CVE-2025-67939

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.6.2.

    Published: 22 Jan 2026
    8.1
    High

    CVE-2025-67938

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Biagiotti biagiotti allows PHP Local File Inclusion.This issue affects Biagiotti: from n/a through < 3.5.2.

    Published: 22 Jan 2026
    7.1
    High

    CVE-2025-67923

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.7.7.

    Published: 22 Jan 2026
    4.3
    Medium

    CVE-2025-67626

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Angel Costa WP SEO Search wp-seo-search allows Cross Site Request Forgery.This issue affects WP SEO Search: from n/a through <= 1.1.

    Published: 22 Jan 2026
    7.1
    High

    CVE-2025-67620

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CleverSoft Anon anon2x allows Reflected XSS.This issue affects Anon: from n/a through <= 2.2.10.

    Published: 22 Jan 2026
    8.8
    High

    CVE-2025-67619

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in designthemes Kids Heaven kids-world allows Object Injection.This issue affects Kids Heaven: from n/a through <= 3.2.

    Published: 22 Jan 2026
    9.8
    Critical

    CVE-2025-67617

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a through <= 1.4.3.

    Published: 22 Jan 2026
    8.1
    High

    CVE-2025-67616

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Mella mella allows PHP Local File Inclusion.This issue affects Mella: from n/a through <= 1.2.29.

    Published: 22 Jan 2026
    8.1
    High

    CVE-2025-67615

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in bslthemes Myour myour allows PHP Local File Inclusion.This issue affects Myour: from n/a through <= 1.5.1.

    Published: 22 Jan 2026
    7.1
    High

    CVE-2025-67614

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheNa thena allows Reflected XSS.This issue affects TheNa: from n/a through <= 1.5.5.

    Published: 22 Jan 2026
    5.4
    Medium

    CVE-2025-66143

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in merkulove Crumber crumber-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crumber: from n/a through <= 1.0.10.

    Published: 22 Jan 2026
    5.4
    Medium

    CVE-2025-66142

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in merkulove Comparimager for Elementor comparimager-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comparimager for Elementor: from n/a through <= 1.0.1.

    Published: 22 Jan 2026
    5.4
    Medium

    CVE-2025-66141

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in merkulove Scroller scroller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scroller: from n/a through <= 2.0.2.

    Published: 22 Jan 2026
    5.4
    Medium

    CVE-2025-66140

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in merkulove Uper for Elementor uper-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uper for Elementor: from n/a through <= 1.0.5.

    Published: 22 Jan 2026
    5.4
    Medium

    CVE-2025-66139

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in merkulove Audier For Elementor audier-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Audier For Elementor: from n/a through <= 1.0.9.

    Published: 22 Jan 2026
    5.4
    Medium

    CVE-2025-66138

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in merkulove Motionger for Elementor motionger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motionger for Elementor: from n/a through <= 2.0.4.

    Published: 22 Jan 2026
    5.4
    Medium

    CVE-2025-66137

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in merkulove Searcher for Elementor searcher-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Searcher for Elementor: from n/a through <= 1.0.3.

    Published: 22 Jan 2026
    5.4
    Medium

    CVE-2025-66136

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in merkulove Carter for Elementor carter-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carter for Elementor: from n/a through <= 1.0.2.

    Published: 22 Jan 2026
    5.4
    Medium

    CVE-2025-66135

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in merkulove Imager for Elementor imager-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Imager for Elementor: from n/a through <= 2.0.4.

    Published: 22 Jan 2026
    4.9
    Medium

    CVE-2025-64252

    Last Modified: 15 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Marco Milesi ANAC XML Viewer anac-xml-viewer allows Server Side Request Forgery.This issue affects ANAC XML Viewer: from n/a through <= 1.8.2.

    Published: 22 Jan 2026
    4.3
    Medium

    CVE-2025-63051

    Last Modified: 15 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in sizam REHub Framework rehub-framework allows Retrieve Embedded Sensitive Data.This issue affects REHub Framework: from n/a through < 19.9.9.4.

    Published: 22 Jan 2026
    6.5
    Medium

    CVE-2025-63026

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant Theme Elements for Elementor grandrestaurant-elementor allows Stored XSS.This issue affects Grand Restaurant Theme Elements for Elementor: from n/a through <= 2.1.1.

    Published: 22 Jan 2026
    5.3
    Medium

    CVE-2025-63019

    Last Modified: 24 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Johan Jonk Stenström Cookies and Content Security Policy cookies-and-content-security-policy allows Retrieve Embedded Sensitive Data.This issue affects Cookies and Content Security Policy: from n/a through <= 2.34.

    Published: 22 Jan 2026
    4.3
    Medium

    CVE-2025-63018

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in wproyal Bard bard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bard: from n/a through <= 2.229.

    Published: 22 Jan 2026
    7.5
    High

    CVE-2025-63017

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes WerkStatt Plugin werkstatt-plugin allows PHP Local File Inclusion.This issue affects WerkStatt Plugin: from n/a through <= 1.6.6.

    Published: 22 Jan 2026
    5.3
    Medium

    CVE-2025-62754

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Kapil Paul Payment Gateway bKash for WC woo-payment-bkash allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway bKash for WC: from n/a through <= 3.1.0.

    Published: 22 Jan 2026
    5.4
    Medium

    CVE-2025-62741

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects Pool Services: from n/a through <= 3.3.

    Published: 22 Jan 2026
    5.4
    Medium

    CVE-2025-62106

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CRM System: from n/a through <= 3.4.5.

    Published: 22 Jan 2026
    5.9
    Medium

    CVE-2025-62077

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SEOSEON EUROPE S.L Affiliate Link Tracker affiliate-link-tracker allows Stored XSS.This issue affects Affiliate Link Tracker: from n/a through <= 0.2.

    Published: 22 Jan 2026
    9.9
    Critical

    CVE-2025-62056

    Last Modified: 15 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <= 1.0.1.

    Published: 22 Jan 2026
    9.9
    Critical

    CVE-2025-62050

    Last Modified: 15 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blogmatic: from n/a through <= 1.0.3.

    Published: 22 Jan 2026
    6.5
    Medium

    CVE-2025-5805

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Electron: from n/a through <= 1.8.2.

    Published: 22 Jan 2026
    8.1
    High

    CVE-2025-54003

    Last Modified: 24 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Depot depot allows PHP Local File Inclusion.This issue affects Depot: from n/a through <= 1.16.

    Published: 22 Jan 2026
    6.5
    Medium

    CVE-2025-54002

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Jthemes xSmart xsmart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects xSmart: from n/a through <= 1.2.9.4.

    Published: 22 Jan 2026
    7.1
    High

    CVE-2025-53240

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamlabs WordPress Photo Gallery photo-gallery-portfolio allows Reflected XSS.This issue affects WordPress Photo Gallery: from n/a through <= 1.1.0.

    Published: 22 Jan 2026
    7.1
    High

    CVE-2025-52762

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio flexo-posts-manager flexo-posts-manager allows Reflected XSS.This issue affects flexo-posts-manager: from n/a through <= 1.0001.

    Published: 22 Jan 2026
    7.1
    High

    CVE-2025-52746

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ayecode Restaurante restaurante allows Reflected XSS.This issue affects Restaurante: from n/a through <= 3.0.7.

    Published: 22 Jan 2026