CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2025-60133

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DJ-Extensions.com PE Easy Slider pe-easy-slider allows Stored XSS.This issue affects PE Easy Slider: from n/a through <= 1.1.0.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60130

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in wedos.com WEDOS Global wgpwpp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WEDOS Global: from n/a through <= 1.2.2.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60129

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Yext Yext yext allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Yext: from n/a through <= 1.1.3.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60128

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WP Delicious Delisho dr-widgets-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Delisho: from n/a through <= 1.1.3.

    Published: 26 Sept 2025
    5.4
    Medium

    CVE-2025-60127

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ArtistScope CopySafe Web Protection wp-copysafe-web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CopySafe Web Protection: from n/a through <= 5.1.

    Published: 26 Sept 2025
    8.8
    High

    CVE-2025-60126

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginOps Testimonial Slider testimonial-add allows PHP Local File Inclusion.This issue affects Testimonial Slider: from n/a through <= 3.5.8.6.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60125

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in themelooks FoodBook foodbook allows Retrieve Embedded Sensitive Data.This issue affects FoodBook: from n/a through <= 4.7.6.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60124

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Hellyer Simple Colorbox simple-colorbox allows Stored XSS.This issue affects Simple Colorbox: from n/a through <= 1.6.1.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60123

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HivePress Claim Listings: from n/a through <= 1.1.3.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60122

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HivePress Claim Listings: from n/a through <= 1.1.4.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60121

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Ex-Themes WooEvents woo-events allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooEvents: from n/a through <= 4.1.7.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60119

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in CoSchedule CoSchedule coschedule-by-todaymade allows Retrieve Embedded Sensitive Data.This issue affects CoSchedule: from n/a through <= 3.3.11.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60120

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPDirectoryKit WP Directory Kit wpdirectorykit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Directory Kit: from n/a through <= 1.4.0.

    Published: 26 Sept 2025
    8.5
    High

    CVE-2025-60118

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Potenzaglobalsolutions PGS Core pgs-core allows SQL Injection.This issue affects PGS Core: from n/a through <= 5.9.0.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60117

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in TangibleWP Vehica Core vehica-core allows Cross Site Request Forgery.This issue affects Vehica Core: from n/a through <= 1.0.100.

    Published: 26 Sept 2025
    5.4
    Medium

    CVE-2025-60116

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Conference Theme Custom Post Type: from n/a through < 2.6.4.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60115

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in instapagedev Instapage Plugin instapage allows Cross Site Request Forgery.This issue affects Instapage Plugin: from n/a through <= 3.7.0.

    Published: 26 Sept 2025
    6.6
    Medium

    CVE-2025-60114

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce YayCurrency yaycurrency allows Code Injection.This issue affects YayCurrency: from n/a through <= 3.3.1.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60113

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in grooni Groovy Menu groovy-menu-free allows Cross Site Request Forgery.This issue affects Groovy Menu: from n/a through <= 1.4.3.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60112

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aThemes Addons for Elementor athemes-addons-for-elementor-lite allows Stored XSS.This issue affects aThemes Addons for Elementor: from n/a through <= 1.1.2.

    Published: 26 Sept 2025
    8.8
    High

    CVE-2025-60111

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in javothemes Javo Core javo-core allows Authentication Bypass.This issue affects Javo Core: from n/a through <= 3.0.0.266.

    Published: 26 Sept 2025
    8.5
    High

    CVE-2025-60110

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup AllInOne - Banner Rotator all-in-one-bannerRotator allows SQL Injection.This issue affects AllInOne - Banner Rotator: from n/a through <= 3.8.

    Published: 26 Sept 2025
    8.5
    High

    CVE-2025-60109

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Content Slider all-in-one-contentSlider allows Blind SQL Injection.This issue affects LambertGroup - AllInOne - Content Slider: from n/a through <= 3.8.

    Published: 26 Sept 2025
    8.5
    High

    CVE-2025-60108

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Thumbnails all-in-one-thumbnailsBanner allows Blind SQL Injection.This issue affects LambertGroup - AllInOne - Banner with Thumbnails: from n/a through <= 3.8.

    Published: 26 Sept 2025
    8.5
    High

    CVE-2025-60107

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Playlist all-in-one-bannerWithPlaylist allows Blind SQL Injection.This issue affects LambertGroup - AllInOne - Banner with Playlist: from n/a through <= 3.8.

    Published: 26 Sept 2025
    4.9
    Medium

    CVE-2025-60106

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Roxnor EmailKit emailkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmailKit: from n/a through <= 1.6.0.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60105

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaphorcreations Ditty ditty-news-ticker allows Stored XSS.This issue affects Ditty: from n/a through <= 3.1.58.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60104

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Gallery Custom Links gallery-custom-links allows Stored XSS.This issue affects Gallery Custom Links: from n/a through <= 2.2.5.

    Published: 26 Sept 2025
    5.4
    Medium

    CVE-2025-60103

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in CridioStudio ListingPro listingpro-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.8.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60102

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront User Role Editor wpfront-user-role-editor allows Stored XSS.This issue affects WPFront User Role Editor: from n/a through <= 4.2.3.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60099

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Embed Any Document embed-any-document allows Stored XSS.This issue affects Embed Any Document: from n/a through <= 2.7.7.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60100

    Last Modified: 23 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through < 9.6.

    Published: 26 Sept 2025
    5.9
    Medium

    CVE-2025-60101

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in duongancol Woostify woostify allows Stored XSS.This issue affects Woostify: from n/a through <= 2.4.2.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60098

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Jeff Farthing Theme My Login theme-my-login allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theme My Login: from n/a through <= 7.1.12.

    Published: 26 Sept 2025
    5.4
    Medium

    CVE-2025-60097

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in CodexThemes TheGem thegem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TheGem: from n/a through <= 5.10.5.

    Published: 26 Sept 2025
    5.4
    Medium

    CVE-2025-60096

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in CodexThemes TheGem (Elementor) thegem-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TheGem (Elementor): from n/a through <= 5.10.5.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60095

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Retrieve Embedded Sensitive Data.This issue affects Stackable: from n/a through <= 3.18.1.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60094

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stackable: from n/a through <= 3.18.1.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-60093

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager download-manager allows Cross Site Request Forgery.This issue affects Download Manager: from n/a through <= 3.3.24.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-60092

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.25.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-60040

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fkrauthan wp-mpdf wp-mpdf allows Stored XSS.This issue affects wp-mpdf: from n/a through <= 3.9.1.

    Published: 26 Sept 2025
    7.1
    High

    CVE-2025-4957

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Reflected XSS.This issue affects ProfileGrid : from n/a through <= 5.9.5.7.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-27006

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeplugs Authorsy authorsy allows Stored XSS.This issue affects Authorsy: from n/a through <= 1.0.5.

    Published: 26 Sept 2025
    7.1
    High

    CVE-2025-48107

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undsgn Uncode uncode allows Reflected XSS.This issue affects Uncode: from n/a through < 2.9.4.4.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-48326

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Acclectic Media Acclectic Media Organizer acclectic-media-organizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Acclectic Media Organizer: from n/a through <= 1.4.

    Published: 26 Sept 2025
    4.3
    Medium

    CVE-2025-58914

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Di Themes Di Themes Demo Site Importer di-themes-demo-site-importer allows Cross Site Request Forgery.This issue affects Di Themes Demo Site Importer: from n/a through <= 1.2.

    Published: 26 Sept 2025
    6.5
    Medium

    CVE-2025-58917

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Verwymeren Quantities and Units for WooCommerce quantities-and-units-for-woocommerce allows Stored XSS.This issue affects Quantities and Units for WooCommerce: from n/a through <= 1.0.13.

    Published: 26 Sept 2025
    5.3
    Medium

    CVE-2025-58919

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in guihom Wide Banner wide-banner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wide Banner: from n/a through <= 1.0.4.

    Published: 26 Sept 2025
    7.1
    High

    CVE-2025-59012

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler traveler allows Reflected XSS.This issue affects Traveler: from n/a through < 3.2.3.

    Published: 26 Sept 2025
    7.7
    High

    CVE-2025-59002

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder bm-builder allows Path Traversal.This issue affects BM Content Builder: from n/a through < 3.16.3.3.

    Published: 26 Sept 2025