CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2025-58266

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fumiki Takahashi Gianism gianism allows Stored XSS.This issue affects Gianism: from n/a through <= 6.0.0.

    Published: 22 Sept 2025
    7.1
    High

    CVE-2025-58267

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Aftabul Islam Stock Message stock-message allows Stored XSS.This issue affects Stock Message: from n/a through <= 1.1.0.

    Published: 22 Sept 2025
    7.1
    High

    CVE-2025-58268

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WPMK WPMK PDF Generator wpmk-pdf-generator allows Stored XSS.This issue affects WPMK PDF Generator: from n/a through <= 1.0.1.

    Published: 22 Sept 2025
    5.3
    Medium

    CVE-2025-58269

    Last Modified: 23 Apr 2026

    Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 2.6.25.

    Published: 22 Sept 2025
    7.1
    High

    CVE-2025-58270

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Cross Site Request Forgery.This issue affects NIX Anti-Spam Light: from n/a through <= 0.0.4.

    Published: 22 Sept 2025
    5.9
    Medium

    CVE-2025-58271

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AnyClip Video Platform AnyClip Luminous Studio anyclip-media allows Stored XSS.This issue affects AnyClip Luminous Studio: from n/a through <= 1.3.3.

    Published: 22 Sept 2025
    5.9
    Medium

    CVE-2025-58645

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gravitate Gravitate Automated Tester gravitate-automated-tester allows Stored XSS.This issue affects Gravitate Automated Tester: from n/a through <= 1.4.5.

    Published: 22 Sept 2025
    5.9
    Medium

    CVE-2025-58646

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chtombleson Mobi2Go mobi2go allows Stored XSS.This issue affects Mobi2Go: from n/a through <= 1.0.0.

    Published: 22 Sept 2025
    5.9
    Medium

    CVE-2025-58647

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Will.I.am Simple Restaurant Menu simple-restaurant-menu allows Stored XSS.This issue affects Simple Restaurant Menu: from n/a through <= 1.2.

    Published: 22 Sept 2025
    6.5
    Medium

    CVE-2025-58648

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicu Micle Simple JWT Login simple-jwt-login allows Stored XSS.This issue affects Simple JWT Login: from n/a through <= 3.6.4.

    Published: 22 Sept 2025
    4.3
    Medium

    CVE-2025-58649

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack allows Retrieve Embedded Sensitive Data.This issue affects All In One SEO Pack: from n/a through <= 4.8.7.1.

    Published: 22 Sept 2025
    5.4
    Medium

    CVE-2025-58650

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All In One SEO Pack: from n/a through <= 4.8.7.1.

    Published: 22 Sept 2025
    6.5
    Medium

    CVE-2025-58651

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PlayerJS PlayerJS playerjs allows DOM-Based XSS.This issue affects PlayerJS: from n/a through <= 2.24.

    Published: 22 Sept 2025
    6.5
    Medium

    CVE-2025-58652

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Carousel Ultimate carousel allows Stored XSS.This issue affects Carousel Ultimate: from n/a through <= 1.8.

    Published: 22 Sept 2025
    6.5
    Medium

    CVE-2025-58653

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JS Morisset JSM file_get_contents() Shortcode wp-file-get-contents allows Stored XSS.This issue affects JSM file_get_contents() Shortcode: from n/a through <= 2.7.1.

    Published: 22 Sept 2025
    6.5
    Medium

    CVE-2025-58654

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-language xili-language allows DOM-Based XSS.This issue affects xili-language: from n/a through <= 2.21.3.

    Published: 22 Sept 2025
    5.9
    Medium

    CVE-2025-58655

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mat Category Featured Images category-featured-images allows Stored XSS.This issue affects Category Featured Images: from n/a through <= 1.1.8.

    Published: 22 Sept 2025
    5.3
    Medium

    CVE-2025-58656

    Last Modified: 23 Apr 2026

    Use of Hard-coded Credentials vulnerability in Risto Niinemets Estonian Shipping Methods for WooCommerce estonian-shipping-methods-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Estonian Shipping Methods for WooCommerce: from n/a through <= 1.7.2.

    Published: 22 Sept 2025
    7.1
    High

    CVE-2025-58657

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in EdwardBock Grid grid allows Stored XSS.This issue affects Grid: from n/a through <= 2.3.1.

    Published: 22 Sept 2025
    5.9
    Medium

    CVE-2025-58658

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proof Factor LLC Proof Factor – Social Proof Notifications proof-factor-social-proof-notifications allows Stored XSS.This issue affects Proof Factor – Social Proof Notifications: from n/a through <= 1.0.5.

    Published: 22 Sept 2025
    5.3
    Medium

    CVE-2025-58659

    Last Modified: 23 Apr 2026

    Use of Hard-coded Credentials vulnerability in Essekia Helpie FAQ helpie-faq allows Retrieve Embedded Sensitive Data.This issue affects Helpie FAQ: from n/a through <= 1.45.

    Published: 22 Sept 2025
    5.4
    Medium

    CVE-2025-58660

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in brandexponents Oshine Core oshine-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oshine Core: from n/a through <= 1.5.5.

    Published: 22 Sept 2025
    5.9
    Medium

    CVE-2025-58661

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eZee Technosys eZee Online Hotel Booking Engine online-booking-engine allows Stored XSS.This issue affects eZee Online Hotel Booking Engine: from n/a through <= 1.0.0.

    Published: 22 Sept 2025
    7.2
    High

    CVE-2025-58662

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injection.This issue affects Awesome Support: from n/a through <= 6.3.5.

    Published: 22 Sept 2025
    4.3
    Medium

    CVE-2025-58663

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Themeum Qubely qubely allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Qubely: from n/a through <= 1.8.14.

    Published: 22 Sept 2025
    4.3
    Medium

    CVE-2025-58664

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Azizul Hasan Text To Speech TTS Accessibility text-to-audio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Text To Speech TTS Accessibility: from n/a through <= 1.9.30.

    Published: 22 Sept 2025
    5.9
    Medium

    CVE-2025-58665

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tmontg1 Form Generator for WordPress form-generator-powered-by-jotform allows Stored XSS.This issue affects Form Generator for WordPress: from n/a through <= 1.52.

    Published: 22 Sept 2025
    4.3
    Medium

    CVE-2025-58666

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Kommo Website Chat Button: Kommo integration website-chat-button-kommo-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Website Chat Button: Kommo integration: from n/a through <= 1.3.1.

    Published: 22 Sept 2025
    5.4
    Medium

    CVE-2025-58667

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in CridioStudio ListingPro Reviews listingpro-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro Reviews: from n/a through < 2.9.11.

    Published: 22 Sept 2025
    4.3
    Medium

    CVE-2025-58668

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in VibeThemes WPLMS wplms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLMS : from n/a through <= 4.970.

    Published: 22 Sept 2025
    5.9
    Medium

    CVE-2025-58669

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modern Minds Magento 2 WordPress Integration m2wp allows Stored XSS.This issue affects Magento 2 WordPress Integration: from n/a through <= 1.4.2.1.

    Published: 22 Sept 2025
    7.1
    High

    CVE-2025-58670

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection wp-content-protection allows Stored XSS.This issue affects WP Content Protection: from n/a through <= 1.3.

    Published: 22 Sept 2025
    7.1
    High

    CVE-2025-58671

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in morganrichards Auction Feed auction-feed allows Stored XSS.This issue affects Auction Feed: from n/a through <= 1.1.4.

    Published: 22 Sept 2025
    5.4
    Medium

    CVE-2025-58672

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.1.12.

    Published: 22 Sept 2025
    5.4
    Medium

    CVE-2025-58673

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12.

    Published: 22 Sept 2025
    4.3
    Medium

    CVE-2025-58675

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in tryinteract Interact: Embed A Quiz On Your Site interact-quiz-embed allows Cross Site Request Forgery.This issue affects Interact: Embed A Quiz On Your Site: from n/a through <= 3.1.

    Published: 22 Sept 2025
    7.1
    High

    CVE-2025-58676

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER horizontal-slider allows Stored XSS.This issue affects HORIZONTAL SLIDER: from n/a through <= 2.4.

    Published: 22 Sept 2025
    7.1
    High

    CVE-2025-58677

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews shrinktheweb-website-preview-plugin allows Stored XSS.This issue affects ShrinkTheWeb (STW) Website Previews: from n/a through <= 2.8.5.

    Published: 22 Sept 2025
    6.5
    Medium

    CVE-2025-58678

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in PickPlugins Accordion accordions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion: from n/a through <= 2.3.15.

    Published: 22 Sept 2025
    5.3
    Medium

    CVE-2025-58679

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in AppMySite AppMySite appmysite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AppMySite: from n/a through <= 3.15.0.

    Published: 22 Sept 2025
    6.5
    Medium

    CVE-2025-58680

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in gutentor Gutentor gutentor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutentor: from n/a through <= 3.5.2.

    Published: 22 Sept 2025
    5.3
    Medium

    CVE-2025-58681

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Jürgen Müller Easy Quotes easy-quotes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Quotes: from n/a through <= 1.2.4.

    Published: 22 Sept 2025
    6.5
    Medium

    CVE-2025-58682

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timur Kamaev Kama Click Counter kama-clic-counter allows Stored XSS.This issue affects Kama Click Counter: from n/a through <= 4.0.4.

    Published: 22 Sept 2025
    6.5
    Medium

    CVE-2025-58683

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luke Mlsna Last Updated Shortcode last-updated-shortcode allows Stored XSS.This issue affects Last Updated Shortcode: from n/a through <= 1.0.1.

    Published: 22 Sept 2025
    6.5
    Medium

    CVE-2025-58684

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase logo-showcase allows Stored XSS.This issue affects Logo Showcase: from n/a through <= 4.0.1.

    Published: 22 Sept 2025
    5.3
    Medium

    CVE-2025-58685

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in cecabank Cecabank WooCommerce Plugin cecabank-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cecabank WooCommerce Plugin: from n/a through <= 0.3.4.

    Published: 22 Sept 2025
    8.5
    High

    CVE-2025-58686

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce perfect-woocommerce-brands allows SQL Injection.This issue affects Perfect Brands for WooCommerce: from n/a through <= 3.6.2.

    Published: 22 Sept 2025
    7.1
    High

    CVE-2025-58687

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP CMS Ninja Current Age Plugin current-age allows Stored XSS.This issue affects Current Age Plugin: from n/a through <= 1.6.

    Published: 22 Sept 2025
    7.1
    High

    CVE-2025-58688

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support the-casengo-chat-widget allows Stored XSS.This issue affects Casengo Live Chat Support: from n/a through <= 2.1.4.

    Published: 22 Sept 2025
    6.5
    Medium

    CVE-2025-58689

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tapfiliate Tapfiliate tapfiliate allows Stored XSS.This issue affects Tapfiliate: from n/a through <= 3.2.2.

    Published: 22 Sept 2025