CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2025-53338

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in dor re.place replace allows Stored XSS.This issue affects re.place: from n/a through <= 0.2.1.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53336

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in abditsori My Resume Builder my-resume-builder allows Stored XSS.This issue affects My Resume Builder: from n/a through <= 1.0.3.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53332

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ethoseo Track Everything track-everything allows Stored XSS.This issue affects Track Everything: from n/a through <= 2.0.1.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53331

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in samcharrington RSS Digest rss-digest allows Stored XSS.This issue affects RSS Digest: from n/a through <= 1.5.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53329

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in szajenw Społecznościowa 6 PL 2013 spolecznosciowa-6-pl-2013 allows Stored XSS.This issue affects Społecznościowa 6 PL 2013: from n/a through <= 2.0.6.

    Published: 27 Jun 2025
    4.3
    Medium

    CVE-2025-53327

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in rui_mashita Aioseo Multibyte Descriptions aioseo-multibyte-descriptions allows Cross Site Request Forgery.This issue affects Aioseo Multibyte Descriptions: from n/a through <= 0.0.6.

    Published: 27 Jun 2025
    5.9
    Medium

    CVE-2025-53325

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dilip kumar Beauty Contact Popup Form beauty-contact-popup-form allows Stored XSS.This issue affects Beauty Contact Popup Form: from n/a through <= 6.0.

    Published: 27 Jun 2025
    4.3
    Medium

    CVE-2025-53323

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in danbriapps Pre-Publish Post Checklist pre-publish-post-checklist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pre-Publish Post Checklist: from n/a through <= 3.1.

    Published: 27 Jun 2025
    5.3
    Medium

    CVE-2025-53322

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Authorize.NET Payments Using Contact Form 7 accept-authorize-net-payments-using-contact-form-7 allows Retrieve Embedded Sensitive Data.This issue affects Accept Authorize.NET Payments Using Contact Form 7: from n/a through <= 2.5.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53321

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Raise The Money Raise The Money raise-the-money allows DOM-Based XSS.This issue affects Raise The Money: from n/a through <= 5.2.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53320

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wp Enhanced Free Downloads EDD allows DOM-Based XSS. This issue affects Free Downloads EDD: from n/a through 1.0.4.

    Published: 27 Jun 2025
    5.4
    Medium

    CVE-2025-53318

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPManiax WP DB Booster wp-db-booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP DB Booster: from n/a through <= 1.0.1.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53317

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in AcmeeDesign WPShapere - WordPress admin theme wpshapere-lite allows Stored XSS.This issue affects WPShapere - WordPress admin theme: from n/a through <= 1.4.1.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53315

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in alanft Relocate Upload relocate-upload allows Stored XSS.This issue affects Relocate Upload: from n/a through <= 0.24.1.

    Published: 27 Jun 2025
    9.6
    Critical

    CVE-2025-53314

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer wp-optimizer allows SQL Injection.This issue affects WP Optimizer: from n/a through <= 2.5.0.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53313

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in plumwd Twitch TV Embed Suite twitch-tv-embed-suite allows Stored XSS.This issue affects Twitch TV Embed Suite: from n/a through <= 2.1.0.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53312

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Looks Awesome OnionBuzz onionbuzz-viral-quiz allows Stored XSS.This issue affects OnionBuzz: from n/a through <= 1.0.7.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53311

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Amol Nirmala Waman Navayan Subscribe navayan-subscribe allows Stored XSS.This issue affects Navayan Subscribe: from n/a through <= 1.13.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53310

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Funnnny HidePost hidepost allows Reflected XSS.This issue affects HidePost: from n/a through <= 2.3.8.

    Published: 27 Jun 2025
    5.3
    Medium

    CVE-2025-53309

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Stripe Payments Using Contact Form 7 accept-stripe-payments-using-contact-form-7 allows Retrieve Embedded Sensitive Data.This issue affects Accept Stripe Payments Using Contact Form 7: from n/a through <= 3.0.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53308

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in gopi_plus Image Slider With Description image-slider-with-description allows Stored XSS.This issue affects Image Slider With Description: from n/a through <= 9.2.

    Published: 27 Jun 2025
    7.6
    High

    CVE-2025-53306

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in lucidcrew WP Forum Server forum-server allows SQL Injection.This issue affects WP Forum Server: from n/a through <= 1.8.2.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53305

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in lucidcrew WP Forum Server forum-server allows Stored XSS.This issue affects WP Forum Server: from n/a through <= 1.8.2.

    Published: 27 Jun 2025
    5.3
    Medium

    CVE-2025-53304

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Rohil Contact Form – 7 : Hide Success Message contact-form-7-hide-success-message allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Contact Form – 7 : Hide Success Message: from n/a through <= 1.1.4.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53301

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Junkie Theme Junkie Team Content theme-junkie-team-content allows DOM-Based XSS.This issue affects Theme Junkie Team Content: from n/a through <= 0.1.1.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53300

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in douglaskarr Podcast Feed Player Widget and Shortcode podcast-feed-player-widget allows Stored XSS.This issue affects Podcast Feed Player Widget and Shortcode: from n/a through <= 2.2.0.

    Published: 27 Jun 2025
    4.9
    Medium

    CVE-2025-53298

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gioni Plugin Inspector plugin-inspector allows Path Traversal.This issue affects Plugin Inspector: from n/a through <= 1.5.

    Published: 27 Jun 2025
    5.9
    Medium

    CVE-2025-53296

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ecoal95 EC Stars Rating ec-stars-rating allows Stored XSS.This issue affects EC Stars Rating: from n/a through <= 1.0.11.

    Published: 27 Jun 2025
    5.3
    Medium

    CVE-2025-53295

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in iCount iCount Payment Gateway icount allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iCount Payment Gateway: from n/a through <= 2.0.7.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53294

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart Agenda smart-agenda-prise-de-rendez-vous-en-ligne allows Stored XSS.This issue affects Smart Agenda: from n/a through <= 4.9.

    Published: 27 Jun 2025
    4.3
    Medium

    CVE-2025-53293

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Morten Dalgaard Johansen Dashboard Widget Sidebar dashboard-widget-sidebar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dashboard Widget Sidebar: from n/a through <= 1.2.3.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53292

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in samsk WP DataTable wp-datatable allows DOM-Based XSS.This issue affects WP DataTable: from n/a through <= 0.2.7.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53290

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MS WP Visual Sitemap wp-visual-sitemap allows Stored XSS.This issue affects WP Visual Sitemap: from n/a through <= 1.0.2.

    Published: 27 Jun 2025
    4.3
    Medium

    CVE-2025-53288

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Adrian Ladó PlatiOnline Payments plationline allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PlatiOnline Payments: from n/a through <= 7.0.0.

    Published: 27 Jun 2025
    5.9
    Medium

    CVE-2025-53287

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Cummings Quick Favicon quick-favicon allows Stored XSS.This issue affects Quick Favicon: from n/a through <= 0.22.8.

    Published: 27 Jun 2025
    5.9
    Medium

    CVE-2025-53285

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Website Flip Add & Replace Affiliate Links for Amazon add-replace-affiliate-links-for-amazon allows Stored XSS.This issue affects Add & Replace Affiliate Links for Amazon: from n/a through <= 1.0.6.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53284

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in pankaj.sakaria CMS Blocks cms-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CMS Blocks: from n/a through <= 1.1.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53282

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Thumbnail Editor thumbnail-editor allows Stored XSS.This issue affects Thumbnail Editor: from n/a through <= 2.3.3.

    Published: 27 Jun 2025
    7.5
    High

    CVE-2025-53281

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPBean WPB Category Slider for WooCommerce wpb-woocommerce-category-slider allows PHP Local File Inclusion.This issue affects WPB Category Slider for WooCommerce: from n/a through <= 1.71.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53280

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football Pool football-pool allows Stored XSS.This issue affects Football Pool: from n/a through <= 2.12.5.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53279

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman Popup addon for Ninja Forms popup-addon-for-ninja-forms allows DOM-Based XSS.This issue affects Popup addon for Ninja Forms: from n/a through <= 3.4.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53278

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter: from n/a through <= 2.6.0.

    Published: 27 Jun 2025
    8.8
    High

    CVE-2025-53277

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Infigo Software IS-theme-companion weblizar-companion allows Object Injection.This issue affects IS-theme-companion: from n/a through <= 1.59.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53276

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress omnipress allows DOM-Based XSS.This issue affects Omnipress: from n/a through <= 1.6.4.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-53275

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka leyka allows DOM-Based XSS.This issue affects Leyka: from n/a through <= 3.32.1.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53274

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Hossin Asaadi WP Permalink Translator wp-permalink-translator allows Stored XSS.This issue affects WP Permalink Translator: from n/a through <= 1.7.6.

    Published: 27 Jun 2025
    4.3
    Medium

    CVE-2025-53273

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Slickstream Slickstream slick-engagement allows Cross Site Request Forgery.This issue affects Slickstream: from n/a through <= 2.0.3.

    Published: 27 Jun 2025
    4.3
    Medium

    CVE-2025-53272

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in opicron Image Cleanup image-cleanup allows Cross Site Request Forgery.This issue affects Image Cleanup: from n/a through <= 1.9.2.

    Published: 27 Jun 2025
    7.1
    High

    CVE-2025-53271

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Anton Bond Additional Order Filters for WooCommerce additional-order-filters-for-woocommerce allows Stored XSS.This issue affects Additional Order Filters for WooCommerce: from n/a through <= 1.22.

    Published: 27 Jun 2025
    4.3
    Medium

    CVE-2025-53270

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Cross Site Request Forgery.This issue affects WordPress CTA: from n/a through <= 1.7.0.

    Published: 27 Jun 2025