CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2025-66117

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form: from n/a through <= 2.7.8.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-66116

    Last Modified: 15 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in UserElements Ultimate Member Widgets for Elementor ultimate-member-widgets-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Ultimate Member Widgets for Elementor: from n/a through <= 2.3.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-66104

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Offload, AI & Optimize with Cloudflare Images: from n/a through <= 1.9.5.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-66102

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Antispam fv-antispam allows Reflected XSS.This issue affects FV Antispam: from n/a through <= 2.7.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-66100

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.3.5.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-66088

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12.

    Published: 18 Dec 2025
    9.1
    Critical

    CVE-2025-66078

    Last Modified: 27 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote Code Inclusion.This issue affects Hotel Booking Lite: from n/a through <= 5.2.3.

    Published: 18 Dec 2025
    9
    Critical

    CVE-2025-66074

    Last Modified: 24 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webhooks: from n/a through <= 3.3.8.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-66070

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.10.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-66068

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.1.9.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-66054

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through <= 4.2.9.4.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-64378

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through < 2.9.10.

    Published: 18 Dec 2025
    8.1
    High

    CVE-2025-64377

    Last Modified: 24 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CridioStudio ListingPro listingpro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through < 2.9.10.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-64376

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro allows Reflected XSS.This issue affects ListingPro: from n/a through < 2.9.10.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-64375

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Mahmudul Hasan Arif WP Social Ninja wp-social-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Social Ninja: from n/a through <= 3.20.1.

    Published: 18 Dec 2025
    9.9
    Critical

    CVE-2025-64374

    Last Modified: 24 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors: from n/a through <= 5.6.81.

    Published: 18 Dec 2025
    8.1
    High

    CVE-2025-64373

    Last Modified: 24 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in shinetheme Traveler traveler allows PHP Local File Inclusion.This issue affects Traveler: from n/a through < 3.2.6.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-64372

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler traveler allows Reflected XSS.This issue affects Traveler: from n/a through < 3.2.6.

    Published: 18 Dec 2025
    8.5
    High

    CVE-2025-64371

    Last Modified: 24 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through < 3.2.6.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-64295

    Last Modified: 15 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack allows Retrieve Embedded Sensitive Data.This issue affects All In One SEO Pack: from n/a through <= 4.8.6.1.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-64273

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-official allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email marketing for WordPress by GetResponse Official: from n/a through <= 1.5.3.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-64272

    Last Modified: 15 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-official allows Retrieve Embedded Sensitive Data.This issue affects Email marketing for WordPress by GetResponse Official: from n/a through <= 1.5.3.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-64270

    Last Modified: 24 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-64268

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through <= 1.0.44.

    Published: 18 Dec 2025
    8.8
    High

    CVE-2025-64266

    Last Modified: 24 Apr 2026

    Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.4.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-64260

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Milesi ANAC XML Bandi di Gara avcp allows Reflected XSS.This issue affects ANAC XML Bandi di Gara: from n/a through <= 7.7.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-64258

    Last Modified: 1 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Retrieve Embedded Sensitive Data.This issue affects Follow My Blog Post: from n/a through <= 2.3.9.

    Published: 18 Dec 2025
    9.8
    Critical

    CVE-2025-64233

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2.8.

    Published: 18 Dec 2025
    9.9
    Critical

    CVE-2025-64231

    Last Modified: 24 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpress-contact-form-7-pdf allows Using Malicious Files.This issue affects WordPress Contact Form 7 PDF, Google Sheet & Database: from n/a through <= 3.0.0.

    Published: 18 Dec 2025
    7.7
    High

    CVE-2025-64230

    Last Modified: 24 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Chill Filr filr-protection allows Path Traversal.This issue affects Filr: from n/a through <= 1.2.10.

    Published: 18 Dec 2025
    9.8
    Critical

    CVE-2025-64227

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-64225

    Last Modified: 24 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in colabrio Stockie Extra stockie-extra allows Code Injection.This issue affects Stockie Extra: from n/a through <= 1.2.11.

    Published: 18 Dec 2025
    8.1
    High

    CVE-2025-64223

    Last Modified: 24 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign PenNews pennews allows PHP Local File Inclusion.This issue affects PenNews: from n/a through < 6.7.3.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-64222

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in FantasticPlugins WooCommerce Recover Abandoned Cart rac allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Recover Abandoned Cart: from n/a through <= 24.6.0.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-64221

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Reservation Plugin dt-reservation-plugin allows Reflected XSS.This issue affects Reservation Plugin: from n/a through <= 1.6.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-64218

    Last Modified: 15 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in WP Chill Passster content-protector allows Retrieve Embedded Sensitive Data.This issue affects Passster: from n/a through <= 4.2.19.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-64217

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography photography allows Reflected XSS.This issue affects Photography: from n/a through <= 7.7.2.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-64214

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-64213

    Last Modified: 15 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Retrieve Embedded Sensitive Data.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-64209

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in StylemixThemes Masterstudy masterstudy allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masterstudy: from n/a through < 4.8.122.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-64207

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Jannah jannah allows DOM-Based XSS.This issue affects Jannah: from n/a through <= 7.6.0.

    Published: 18 Dec 2025
    9.8
    Critical

    CVE-2025-64206

    Last Modified: 24 Apr 2026

    Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jannah: from n/a through <= 7.6.0.

    Published: 18 Dec 2025
    8.1
    High

    CVE-2025-64205

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local File Inclusion.This issue affects Jannah: from n/a through <= 7.6.0.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-64203

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster mailster allows Reflected XSS.This issue affects Mailster: from n/a through < 4.1.14.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-64193

    Last Modified: 24 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in 8theme XStore xstore allows PHP Local File Inclusion.This issue affects XStore: from n/a through < 9.6.1.

    Published: 18 Dec 2025
    6.3
    Medium

    CVE-2025-64192

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects XStore: from n/a through < 9.6.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-64191

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows Reflected XSS.This issue affects XStore: from n/a through < 9.6.1.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-64189

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through < 5.6.

    Published: 18 Dec 2025
    9.8
    Critical

    CVE-2025-64188

    Last Modified: 15 Apr 2026

    Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9.

    Published: 18 Dec 2025
    8.1
    High

    CVE-2025-6326

    Last Modified: 24 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Inset inset allows PHP Local File Inclusion.This issue affects Inset: from n/a through <= 1.18.0.

    Published: 18 Dec 2025