CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-20733

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00441509; Issue ID: MSV-4138.

    Published: 4 Nov 2025
    6.7
    Medium

    CVE-2025-20730

    Last Modified: 26 Feb 2026

    In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10068463; Issue ID: MSV-4141.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-20728

    Last Modified: 26 Feb 2026

    In wlan STA driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00447115; Issue ID: MSV-4276.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-20725

    Last Modified: 26 Feb 2026

    In ims service, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01671924; Issue ID: MSV-4620.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-20726

    Last Modified: 26 Feb 2026

    In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01672598; Issue ID: MSV-4622.

    Published: 4 Nov 2025
    8.1
    High

    CVE-2025-20727

    Last Modified: 26 Feb 2026

    In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01672601; Issue ID: MSV-4623.

    Published: 4 Nov 2025
    4.4
    Medium

    CVE-2025-12396

    Last Modified: 21 Apr 2026

    The clubmember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 4 Nov 2025
    6.4
    Medium

    CVE-2025-11812

    Last Modified: 21 Apr 2026

    The Reuse Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reuse_builder_single_post_title' shortcode in all versions up to, and including, 1.7. This is due to insufficient input sanitization and output escaping on the 'style' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-12403

    Last Modified: 21 Apr 2026

    The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to missing or incorrect nonce validation on the brzon_admin_panel() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    4.4
    Medium

    CVE-2025-11753

    Last Modified: 22 Apr 2026

    The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 4 Nov 2025
    9.8
    Critical

    CVE-2025-12158

    Last Modified: 21 Apr 2026

    The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the suc_submit_capabilities() function in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to elevate the role of any user account to administrator.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-12452

    Last Modified: 15 Apr 2026

    The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the widgets.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    7.2
    High

    CVE-2025-11733

    Last Modified: 21 Apr 2026

    The Footnotes Made Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 3.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Nov 2025
    4.4
    Medium

    CVE-2025-12065

    Last Modified: 21 Apr 2026

    The WP Carticon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carticon_js_script' parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 4 Nov 2025
    4.4
    Medium

    CVE-2025-12371

    Last Modified: 21 Apr 2026

    The Nari Accountant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via account settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-12389

    Last Modified: 21 Apr 2026

    The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_setting() function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's record setting.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-11704

    Last Modified: 22 Apr 2026

    The Elegance Menu plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the 'elegance-menu' attribute of the `elegance-menu` shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-12402

    Last Modified: 22 Apr 2026

    The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.00. This is due to missing or incorrect nonce validation on the linkedinresume_printAdminPage() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-12415

    Last Modified: 21 Apr 2026

    The MapMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the admin_shortcode_submit, admin_configuration_submit, and admin_shortcode_delete functions. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-12156

    Last Modified: 15 Apr 2026

    The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_post_data() function in versions 2.0.7 to 2.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create and publish arbitrary posts.

    Published: 4 Nov 2025
    8.8
    High

    CVE-2025-11724

    Last Modified: 22 Apr 2026

    The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all versions up to, and including, 3.2.3. This is due to missing file type validation in the EMBM_Admin_Untappd_Import_image() function and missing authorization checks on the wp_ajax_embm-untappd-import action. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files including PHP files and execute code on the server granted they can provide a mock HTTP server that responds with specific JSON data.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-12456

    Last Modified: 22 Apr 2026

    The Centangle-Team plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to modify plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Additionally, due to insufficient input sanitization and output escaping on cai_name_color parameter, this issue allows to inject arbitrary web scripts in pages, that will execute whenever a user accesses an injected page.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-12400

    Last Modified: 22 Apr 2026

    The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on the manage_page() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    6.4
    Medium

    CVE-2025-12369

    Last Modified: 22 Apr 2026

    The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `geojsonmarker` shortcode in all versions up to, and including, 4.7. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-11890

    Last Modified: 22 Apr 2026

    The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a payments status through server-side validation though the /wc-api/bp-payeer-gateway-callback endpoint. This makes it possible for unauthenticated attackers to update unpaid order statuses to paid resulting in a loss of revenue.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-12157

    Last Modified: 22 Apr 2026

    The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_reset_capability' AJAX endpoint in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to reset any user's capabilities.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-12410

    Last Modified: 22 Apr 2026

    The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation in the sh_contextual_help_dashboard_widget() function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    6.5
    Medium

    CVE-2025-11758

    Last Modified: 15 Apr 2026

    The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization check in all versions up to, and including, 2.0.3. This is due to the plugin exposing admin-level AJAX actions to unauthenticated users via wp_ajax_nopriv_ hooks, while relying only on a nonce check without capability checks. This makes it possible for unauthenticated attackers to create published pages, create shift records with integrity issues, and download time reports containing PII (employee names and work schedules).

    Published: 4 Nov 2025
    5.4
    Medium

    CVE-2025-12413

    Last Modified: 22 Apr 2026

    The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the smWpCfSwOptions() function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-12350

    Last Modified: 15 Apr 2026

    The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admin_action AJAX endpoint in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update plugin settings.

    Published: 4 Nov 2025
    4.4
    Medium

    CVE-2025-12393

    Last Modified: 22 Apr 2026

    The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-12416

    Last Modified: 22 Apr 2026

    The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the pr_save_settings() function and insufficient input sanitization. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The injected scripts will execute whenever a user accesses the plugin's settings page.

    Published: 4 Nov 2025
    8.8
    High

    CVE-2025-10896

    Last Modified: 22 Apr 2026

    Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of File with Dangerous Type via arbitrary plugin installation in all versions up to, and including, 1.0.2.3. This is due to missing capability checks on the '*_recommended_upgrade_plugin' function which allows arbitrary plugin URLs to be installed. This makes it possible for authenticated attackers with subscriber-level access and above to upload arbitrary plugin packages to the affected site's server via a crafted plugin URL, which may make remote code execution possible.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-12412

    Last Modified: 15 Apr 2026

    The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation on th tbn_ajax_add() function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-12188

    Last Modified: 22 Apr 2026

    The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the 'wpm_navigation_links_settings' page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    5.8
    Medium

    CVE-2025-12683

    Last Modified: 15 Apr 2026

    The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained with other elements) for a local low privilege user.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-12069

    Last Modified: 22 Apr 2026

    The WP Global Screen Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing nonce validation on the `updatewpglobalscreenoptions` action handler. This makes it possible for unauthenticated attackers to modify global screen options for all users via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    9.8
    Critical

    CVE-2025-11008

    Last Modified: 22 Apr 2026

    The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the log file. This makes it possible for unauthenticated attackers to extract sensitive data including authentication credentials, which can be used to log in as other users as long as they have used the plugin's custom authentication feature before. This may include administrators, which makes a complete site takeover possible.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-12401

    Last Modified: 22 Apr 2026

    The Label Plugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect nonce validation on the label_plugins_options() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    9.8
    Critical

    CVE-2025-11007

    Last Modified: 15 Apr 2026

    The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the wp_ajax_nopriv_ce21_single_sign_on_save_api_settings AJAX action in versions 2.2.1 to 2.3.1. This makes it possible for unauthenticated attackers to update the plugin's API settings including a secret key used for authentication. This allows unauthenticated attackers to create new admin accounts on an affected site.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-12070

    Last Modified: 22 Apr 2026

    The ViaAds plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing nonce validation on the `ViaAds_pluginHandler` function. This makes it possible for unauthenticated attackers to modify the plugin's API key and cookie consent settings via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

    Published: 4 Nov 2025
    6.5
    Medium

    CVE-2025-47370

    Last Modified: 5 Nov 2025

    Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-47368

    Last Modified: 26 Feb 2026

    Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-47367

    Last Modified: 26 Feb 2026

    Memory corruption while accessing a buffer during IOCTL processing.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-47365

    Last Modified: 26 Feb 2026

    Memory corruption while processing large input data from a remote source via a communication interface.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-47362

    Last Modified: 5 Nov 2025

    Information disclosure while processing message from client with invalid payload.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-47361

    Last Modified: 26 Feb 2026

    Memory corruption when triggering a subsystem crash with an out-of-range identifier.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-47360

    Last Modified: 26 Feb 2026

    Memory corruption while processing client message during device management.

    Published: 4 Nov 2025
    8
    High

    CVE-2025-47357

    Last Modified: 5 Nov 2025

    Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-47353

    Last Modified: 26 Feb 2026

    Memory corruption while processing request sent from GVM.

    Published: 4 Nov 2025