CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2025-60181

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in silence Silencesoft RSS Reader external-rss-reader allows Server Side Request Forgery.This issue affects Silencesoft RSS Reader: from n/a through <= 0.6.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60179

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Space Studio Click & Tweet allows Stored XSS. This issue affects Click & Tweet: from n/a through 0.8.9.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60177

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rozx Recaptcha – wp recaptcha-wp allows Stored XSS.This issue affects Recaptcha – wp: from n/a through <= 0.2.6.

    Published: 26 Sept 2025
    7.1
    High

    CVE-2025-60173

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ashwani kumar GST for WooCommerce gst-for-woocommerce allows Stored XSS.This issue affects GST for WooCommerce: from n/a through <= 2.0.

    Published: 26 Sept 2025
    7.1
    High

    CVE-2025-60172

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in flytedesk Flytedesk Digital flytedesk-digital allows Stored XSS.This issue affects Flytedesk Digital: from n/a through <= 20181101.

    Published: 26 Sept 2025
    7.1
    High

    CVE-2025-60171

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in yourplugins Conditional Cart Messages for WooCommerce – YourPlugins.com yourplugins-wc-conditional-cart-notices allows Stored XSS.This issue affects Conditional Cart Messages for WooCommerce – YourPlugins.com: from n/a through <= 1.2.10.

    Published: 26 Sept 2025
    7.1
    High

    CVE-2025-60170

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Taraprasad Swain HTACCESS IP Blocker htaccess-ip-blocker allows Stored XSS.This issue affects HTACCESS IP Blocker: from n/a through <= 1.0.

    Published: 26 Sept 2025
    7.1
    High

    CVE-2025-60169

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in W3S Cloud Technology W3SCloud Contact Form 7 to Zoho CRM w3s-cf7-zoho allows Stored XSS.This issue affects W3SCloud Contact Form 7 to Zoho CRM: from n/a through <= 3.2.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60167

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in honzat Page Manager for Elementor page-manager-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Page Manager for Elementor: from n/a through <= 2.0.5.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60166

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in wpshuffle WP Subscription Forms PRO wp-subscription-forms-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Subscription Forms PRO: from n/a through <= 2.0.5.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60165

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in HaruTheme Frames frames allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frames: from n/a through <= 1.5.7.

    Published: 26 Sept 2025
    7.1
    High

    CVE-2025-60164

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in NewsMAN NewsmanApp newsmanapp allows Stored XSS.This issue affects NewsmanApp: from n/a through <= 2.7.7.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60163

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robin W bbp topic count bbp-topic-count allows DOM-Based XSS.This issue affects bbp topic count: from n/a through <= 3.2.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60162

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows DOM-Based XSS.This issue affects Job Board Manager: from n/a through <= 2.1.61.

    Published: 26 Sept 2025
    5.4
    Medium

    CVE-2025-60161

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in bdthemes ZoloBlocks zoloblocks allows Server Side Request Forgery.This issue affects ZoloBlocks: from n/a through <= 2.3.11.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60160

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sharkthemes Smart Related Products ai-related-products allows Stored XSS.This issue affects Smart Related Products: from n/a through <= 2.0.8.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60159

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nota Fiscal Eletrônica WooCommerce: from n/a through <= 3.4.0.9.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60158

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce allows Stored XSS.This issue affects Nota Fiscal Eletrônica WooCommerce: from n/a through <= 3.4.0.9.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60157

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket System wp-ticket allows Stored XSS.This issue affects WP Ticket Customer Service Software & Support Ticket System: from n/a through <= 6.0.2.

    Published: 26 Sept 2025
    9.6
    Critical

    CVE-2025-60156

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: from n/a through <= 8.34.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60155

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Virtual Assistant: from n/a through <= 3.0.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60154

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jennifer Moss MWW Disclaimer Buttons mww-disclaimer-buttons allows Stored XSS.This issue affects MWW Disclaimer Buttons: from n/a through <= 3.41.

    Published: 26 Sept 2025
    7.5
    High

    CVE-2025-60153

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe To Unlock subscribe-to-unlock allows PHP Local File Inclusion.This issue affects Subscribe To Unlock: from n/a through <= 1.1.5.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60152

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in wpshuffle Subscribe To Unlock subscribe-to-unlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe To Unlock: from n/a through <= 1.1.5.

    Published: 26 Sept 2025
    7.5
    High

    CVE-2025-60150

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows PHP Local File Inclusion.This issue affects Subscribe to Download: from n/a through <= 2.0.9.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60149

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rocket Apps Notely notely allows Stored XSS.This issue affects Notely: from n/a through <= 1.8.0.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60148

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe to Download: from n/a through <= 2.0.9.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60147

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Feed ht-instagram allows Stored XSS.This issue affects HT Feed: from n/a through <= 1.3.0.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60146

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amit Verma Map Categories to Pages map-categories-to-pages allows Stored XSS.This issue affects Map Categories to Pages: from n/a through <= 1.3.2.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60145

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in yonifre Lenix scss compiler lenix-scss-compiler allows Cross Site Request Forgery.This issue affects Lenix scss compiler: from n/a through <= 1.2.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60144

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yonifre Lenix scss compiler lenix-scss-compiler allows Stored XSS.This issue affects Lenix scss compiler: from n/a through <= 1.2.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60143

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in netgsm Netgsm netgsm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Netgsm: from n/a through <= 2.9.69.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60142

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DaganLev Simple Meta Tags simple-meta-tags allows DOM-Based XSS.This issue affects Simple Meta Tags: from n/a through <= 1.5.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60141

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thetechtribe The Tribal the-tech-tribe allows Stored XSS.This issue affects The Tribal: from n/a through <= 1.3.3.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60140

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal the-tech-tribe allows Retrieve Embedded Sensitive Data.This issue affects The Tribal: from n/a through <= 1.3.3.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60139

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Joovii Sendle Shipping official-sendle-shipping-method allows Cross Site Request Forgery.This issue affects Sendle Shipping: from n/a through <= 6.02.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60138

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a through <= 2.6.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60137

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Post Featured Video post-featured-video allows Cross Site Request Forgery.This issue affects Post Featured Video: from n/a through <= 1.7.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60136

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cartpauj User Notes user-notes allows Stored XSS.This issue affects User Notes: from n/a through <= 1.0.2.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60133

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DJ-Extensions.com PE Easy Slider pe-easy-slider allows Stored XSS.This issue affects PE Easy Slider: from n/a through <= 1.1.0.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60130

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in wedos.com WEDOS Global wgpwpp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WEDOS Global: from n/a through <= 1.2.2.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60129

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Yext Yext yext allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Yext: from n/a through <= 1.1.3.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60128

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WP Delicious Delisho dr-widgets-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Delisho: from n/a through <= 1.1.3.

    Published: 26 Sept 2025
    5.4
    Medium

    CVE-2025-60127

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ArtistScope CopySafe Web Protection wp-copysafe-web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CopySafe Web Protection: from n/a through <= 5.1.

    Published: 26 Sept 2025
    8.8
    High

    CVE-2025-60126

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginOps Testimonial Slider testimonial-add allows PHP Local File Inclusion.This issue affects Testimonial Slider: from n/a through <= 3.5.8.6.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60125

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in themelooks FoodBook foodbook allows Retrieve Embedded Sensitive Data.This issue affects FoodBook: from n/a through <= 4.7.6.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60124

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Hellyer Simple Colorbox simple-colorbox allows Stored XSS.This issue affects Simple Colorbox: from n/a through <= 1.6.1.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60123

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HivePress Claim Listings: from n/a through <= 1.1.3.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60122

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HivePress Claim Listings: from n/a through <= 1.1.4.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60121

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Ex-Themes WooEvents woo-events allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooEvents: from n/a through <= 4.1.7.

    Published: 26 Sept 2025