CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2025-10129

    Last Modified: 22 Apr 2026

    The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Oct 2025
    4.3
    Medium

    CVE-2025-10375

    Last Modified: 21 Apr 2026

    The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10. This is due to missing nonce validation on multiple AJAX actions including accessibe_signup, accessibe_login, accessibe_license_trial, accessibe_modify_config, and accessibe_add_verification_page. This makes it possible for unauthenticated attackers to modify plugin settings and create verification files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 11 Oct 2025
    4.9
    Medium

    CVE-2025-9947

    Last Modified: 20 Apr 2026

    The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versions up to, and including, 3.12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 11 Oct 2025
    2.4
    Low

    CVE-2025-8606

    Last Modified: 20 Apr 2026

    The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 1.3.23. This is due to missing or incorrect nonce validation on the activate_plugin and deactivate_plugin functions. This makes it possible for attackers to trick authenticated administrators into activating or deactivating specified plugins via a forged request, such as clicking on a malicious link or visiting a compromised page.

    Published: 11 Oct 2025
    6.5
    Medium

    CVE-2025-10175

    Last Modified: 21 Apr 2026

    The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 11 Oct 2025
    8.8
    High

    CVE-2025-8593

    Last Modified: 20 Apr 2026

    The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is due to a missing capability check on the 'install_plugin' function. This makes it possible for authenticated attackers, with subscriber-level access and above to install plugins on the target site and potentially achieve arbitrary code execution on the server under certain conditions.

    Published: 11 Oct 2025
    5.3
    Medium

    CVE-2025-8484

    Last Modified: 20 Apr 2026

    The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

    Published: 11 Oct 2025
    4.9
    Medium

    CVE-2025-9950

    Last Modified: 21 Apr 2026

    The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.6 via the rrrlgvwr_get_file function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

    Published: 11 Oct 2025
    4.3
    Medium

    CVE-2025-8682

    Last Modified: 22 Apr 2026

    The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the newsup_admin_info_install_plugin() function in all versions up to, and including, 5.0.10. This makes it possible for unauthenticated attackers to install the ansar-import plugin.

    Published: 11 Oct 2025
    4.3
    Medium

    CVE-2025-9626

    Last Modified: 22 Apr 2026

    The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the admin_process_widget_page_change function. This makes it possible for unauthenticated attackers to modify widget page block configurations via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 11 Oct 2025
    6.4
    Medium

    CVE-2025-10190

    Last Modified: 22 Apr 2026

    The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortcode in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Oct 2025
    6.8
    Medium

    CVE-2025-9975

    Last Modified: 21 Apr 2026

    The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.8.1 via the wp_scraper_extract_content function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. On Cloud instances, this issue allows for metadata retrieving.

    Published: 11 Oct 2025
    9.8
    Critical

    CVE-2025-6439

    Last Modified: 21 Apr 2026

    The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for unauthenticated attackers to delete all files in an arbitrary directory on the server, which can lead to remote code execution, data loss, or site unavailability.

    Published: 11 Oct 2025
    6.4
    Medium

    CVE-2025-7652

    Last Modified: 22 Apr 2026

    The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Oct 2025
    6.4
    Medium

    CVE-2025-10167

    Last Modified: 22 Apr 2026

    The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_stock_snapshot_restocked shortcode in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Oct 2025
    4.3
    Medium

    CVE-2025-9621

    Last Modified: 22 Apr 2026

    The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.1. This is due to missing or incorrect nonce validation on the wpcmt_sync action in the wpcmt_request_handler function. This makes it possible for unauthenticated attackers to trigger comment synchronization events via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 11 Oct 2025
    5.5
    Medium

    CVE-2025-58293

    Last Modified: 20 Oct 2025

    Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    5.9
    Medium

    CVE-2025-58289

    Last Modified: 20 Oct 2025

    Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    6.2
    Medium

    CVE-2025-58301

    Last Modified: 20 Oct 2025

    Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    6.2
    Medium

    CVE-2025-58300

    Last Modified: 20 Oct 2025

    Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    8.4
    High

    CVE-2025-58299

    Last Modified: 20 Oct 2025

    Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    7.3
    High

    CVE-2025-58298

    Last Modified: 20 Oct 2025

    Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    5.5
    Medium

    CVE-2025-11594

    Last Modified: 15 Apr 2026

    A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file /index.php of the component Quantity Handler. Such manipulation leads to improper validation of specified quantity in input. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.

    Published: 11 Oct 2025
    5.9
    Medium

    CVE-2025-58297

    Last Modified: 20 Oct 2025

    Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    5.9
    Medium

    CVE-2025-58295

    Last Modified: 20 Oct 2025

    Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    3.3
    Low

    CVE-2025-58292

    Last Modified: 20 Oct 2025

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    3.3
    Low

    CVE-2025-58291

    Last Modified: 20 Oct 2025

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    3.3
    Low

    CVE-2025-58290

    Last Modified: 21 Oct 2025

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    5.5
    Medium

    CVE-2025-58288

    Last Modified: 20 Oct 2025

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    7.8
    High

    CVE-2025-58287

    Last Modified: 20 Oct 2025

    Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2025
    3.3
    Low

    CVE-2025-58286

    Last Modified: 20 Oct 2025

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2025
    4.7
    Medium

    CVE-2025-11167

    Last Modified: 21 Apr 2026

    The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.5.6. This is due to insufficient validation on the redirect url supplied via the 'redirect_url' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

    Published: 11 Oct 2025
    5.3
    Medium

    CVE-2025-11518

    Last Modified: 21 Apr 2026

    The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via several wishlist AJAX functions due to missing validation on a user controlled key that is exposed when wishlists are shared. This makes it possible for unauthenticated attackers to empty and add to other user's wishlists, if they have access to the key.

    Published: 11 Oct 2025
    4.3
    Medium

    CVE-2025-11254

    Last Modified: 22 Apr 2026

    The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

    Published: 11 Oct 2025
    9.8
    Critical

    CVE-2025-6553

    Last Modified: 22 Apr 2026

    The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_checkout() function in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 11 Oct 2025
    4.9
    Medium

    CVE-2025-10185

    Last Modified: 21 Apr 2026

    The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the action nf_load_form_entries in all versions up to, and including, 9.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This may be exploitable by lower-level users if access is granted by a site administrator.

    Published: 11 Oct 2025
    4.9
    Medium

    CVE-2025-10048

    Last Modified: 22 Apr 2026

    The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 3.6.31 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 11 Oct 2025
    5.3
    Medium

    CVE-2025-9196

    Last Modified: 21 Apr 2026

    The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file that gets created on install. This makes it possible for unauthenticated attackers to extract sensitive data including configuration data.

    Published: 11 Oct 2025
    6.4
    Medium

    CVE-2025-11197

    Last Modified: 22 Apr 2026

    The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Oct 2025
    9.8
    Critical

    CVE-2025-11533

    Last Modified: 15 Apr 2026

    The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. This is due to the process_register() function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

    Published: 11 Oct 2025
    6.4
    Medium

    CVE-2025-9496

    Last Modified: 22 Apr 2026

    The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Oct 2025
    2.1
    Low

    CVE-2025-11593

    Last Modified: 24 Feb 2026

    A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin/actions/delete-equipment.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

    Published: 11 Oct 2025
    2.1
    Low

    CVE-2025-11592

    Last Modified: 24 Feb 2026

    A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edit-equipmentform.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.

    Published: 11 Oct 2025
    2.1
    Low

    CVE-2025-11591

    Last Modified: 24 Feb 2026

    A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/actions/delete-member.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

    Published: 11 Oct 2025
    5.3
    Medium

    CVE-2025-58285

    Last Modified: 20 Oct 2025

    Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2025
    5.9
    Medium

    CVE-2025-58284

    Last Modified: 20 Oct 2025

    Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2025
    5.5
    Medium

    CVE-2025-58283

    Last Modified: 20 Oct 2025

    Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2025
    2.8
    Low

    CVE-2025-58282

    Last Modified: 20 Oct 2025

    Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2025
    6.2
    Medium

    CVE-2025-58278

    Last Modified: 21 Oct 2025

    Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2025
    4
    Medium

    CVE-2025-58277

    Last Modified: 22 Oct 2025

    Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2025