CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-11299

    Last Modified: 8 Apr 2026

    The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.37 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.

    Published: 22 Apr 2025
    6.4
    Medium

    CVE-2025-3458

    Last Modified: 21 Apr 2026

    The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The Classic Editor plugin must be installed and activated to exploit the vulnerability.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-3472

    Last Modified: 21 Apr 2026

    The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.

    Published: 22 Apr 2025
    6.4
    Medium

    CVE-2025-3457

    Last Modified: 21 Apr 2026

    The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortcode in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46254

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through <= 45.10.0.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46253

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit gutenkit-blocks-addon allows Stored XSS.This issue affects GutenKit: from n/a through <= 2.2.2.

    Published: 22 Apr 2025
    7.6
    High

    CVE-2025-46252

    Last Modified: 24 Aug 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.2.

    Published: 22 Apr 2025
    7.1
    High

    CVE-2025-46251

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Cross Site Request Forgery.This issue affects VikRestaurants: from n/a through <= 1.3.3.

    Published: 22 Apr 2025
    5.9
    Medium

    CVE-2025-46250

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VPSUForm v-form allows Stored XSS.This issue affects VPSUForm: from n/a through <= 3.1.14.

    Published: 22 Apr 2025
    4.3
    Medium

    CVE-2025-46249

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor simple-calendar-for-elementor allows Cross Site Request Forgery.This issue affects Simple calendar for Elementor: from n/a through <= 1.6.4.

    Published: 22 Apr 2025
    5.3
    Medium

    CVE-2025-46247

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.

    Published: 22 Apr 2025
    4.3
    Medium

    CVE-2025-46246

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Request Forgery.This issue affects CM Answers: from n/a through <= 3.3.3.

    Published: 22 Apr 2025
    4.3
    Medium

    CVE-2025-46245

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site Request Forgery.This issue affects CM Ad Changer: from n/a through <= 2.0.5.

    Published: 22 Apr 2025
    5.3
    Medium

    CVE-2025-46244

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Linked Variations for Woocommerce: from n/a through <= 1.0.3.

    Published: 22 Apr 2025
    4.3
    Medium

    CVE-2025-46243

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abandoned-cart allows Cross Site Request Forgery.This issue affects Recover abandoned cart for WooCommerce: from n/a through <= 2.2.

    Published: 22 Apr 2025
    7.6
    High

    CVE-2025-46242

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu allows SQL Injection.This issue affects Watu Quiz: from n/a through <= 3.4.3.

    Published: 22 Apr 2025
    8.2
    High

    CVE-2025-46241

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46240

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter simple-download-counter allows Stored XSS.This issue affects Simple Download Counter: from n/a through <= 2.2.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46239

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme Switcha theme-switcha allows Stored XSS.This issue affects Theme Switcha: from n/a through <= 3.4.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46238

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer List Last Changes list-last-changes allows Stored XSS.This issue affects List Last Changes: from n/a through <= 1.2.1.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46237

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Stored XSS.This issue affects Link Library: from n/a through <= 7.8.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46236

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms html-forms allows Stored XSS.This issue affects HTML Forms: from n/a through <= 1.5.2.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46235

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a through <= 2.0.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46233

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv sirv allows Stored XSS.This issue affects Sirv: from n/a through <= 7.5.3.

    Published: 22 Apr 2025
    4.3
    Medium

    CVE-2025-46232

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Alt Text AI: from n/a through <= 1.9.93.

    Published: 22 Apr 2025
    5.4
    Medium

    CVE-2025-46231

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Cross Site Request Forgery.This issue affects affiliate-toolkit: from n/a through <= 3.7.3.

    Published: 22 Apr 2025
    5.9
    Medium

    CVE-2025-46229

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics webtexttool allows Stored XSS.This issue affects Textmetrics: from n/a through <= 3.6.2.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46228

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows DOM-Based XSS.This issue affects Event post: from n/a through <= 5.9.11.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46227

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brecht Custom Related Posts custom-related-posts allows Stored XSS.This issue affects Custom Related Posts: from n/a through <= 1.7.4.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46226

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ferranfg MPL-Publisher mpl-publisher allows Stored XSS.This issue affects MPL-Publisher: from n/a through <= 2.18.0.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-46225

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in page for Elementor allows DOM-Based XSS. This issue affects Post in page for Elementor: from n/a through 1.0.1.

    Published: 22 Apr 2025
    7
    High

    CVE-2025-3519

    Last Modified: 15 Apr 2026

    An authorization bypass in Unblu Spark allows a participant of a conversation to replace an existing, uploaded file. Every uploaded file in Unblu gets assigned with a randomly generated Universally Unique ID (UUID). In case a participant of this or another conversation gets access to such a file ID, it can be used to replace the file without changing the file name and details or the name of the user who uploaded the file. During the upload, file interception and allowed file type rules are still applied correctly.

    Published: 22 Apr 2025
    5.3
    Medium

    CVE-2025-3518

    Last Modified: 23 Jun 2025

    It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabled. The file upload functionality can be enabled or disabled for specific use cases through configuration. In case the functionality is disabled for at least one use case, the system nevertheless allows files to be uploaded through direct API requests. During the upload file, interception and allowed file type rules are still applied correctly. If file sharing is generally enabled, this issue is not of concern.

    Published: 22 Apr 2025
    —
    Unknown

    CVE-2025-46216

    Last Modified: 23 Apr 2025

    Not used

    Published: 22 Apr 2025
    —
    Unknown

    CVE-2025-46217

    Last Modified: 23 Apr 2025

    Not used

    Published: 22 Apr 2025
    —
    Unknown

    CVE-2025-46218

    Last Modified: 23 Apr 2025

    Not used

    Published: 22 Apr 2025
    —
    Unknown

    CVE-2025-46219

    Last Modified: 23 Apr 2025

    Not used

    Published: 22 Apr 2025
    —
    Unknown

    CVE-2025-46220

    Last Modified: 23 Apr 2025

    Not used

    Published: 22 Apr 2025
    —
    Unknown

    CVE-2025-46221

    Last Modified: 23 Apr 2025

    Not used

    Published: 22 Apr 2025
    —
    Unknown

    CVE-2025-46222

    Last Modified: 23 Apr 2025

    Not used

    Published: 22 Apr 2025
    —
    Unknown

    CVE-2025-46223

    Last Modified: 23 Apr 2025

    Not used

    Published: 22 Apr 2025
    —
    Unknown

    CVE-2025-46224

    Last Modified: 23 Apr 2025

    Not used

    Published: 22 Apr 2025
    7.5
    High

    CVE-2025-26413

    Last Modified: 23 Jun 2025

    Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is  out of range. This issue affects Apache Kvrocks: through 2.11.1. Users are recommended to upgrade to version 2.12.0, which fixes the issue.

    Published: 22 Apr 2025
    8.1
    High

    CVE-2025-2594

    Last Modified: 30 Sept 2025

    The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.

    Published: 22 Apr 2025
    6.4
    Medium

    CVE-2025-3814

    Last Modified: 20 Apr 2026

    The Tax Switch for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class-name’ parameter in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Apr 2025
    6.4
    Medium

    CVE-2025-2839

    Last Modified: 21 Apr 2026

    The WP Import Export Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpiePreviewData’ function in all versions up to, and including, 3.9.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Apr 2025
    8.8
    High

    CVE-2025-3616

    Last Modified: 28 May 2025

    The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb_make_proxy_api_request() function in versions 11.4 to 11.4.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The arbitrary file upload was sufficiently patched in 11.4.5, but a capability check was added in 11.4.6 to properly prevent unauthorized limited file uploads.

    Published: 22 Apr 2025
    7.1
    High

    CVE-2024-46899

    Last Modified: 15 Apr 2026

    Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentials leakage vulnerability.This issue affects Hitachi Ops Center Common Services: from 10.0.0-00 before 11.0.0-04; Hitachi Ops Center Analyzer viewpoint OVF: from 10.0.0-00 before 11.0.0-04.

    Published: 22 Apr 2025
    5.5
    Medium

    CVE-2025-2300

    Last Modified: 15 Apr 2026

    Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00.

    Published: 22 Apr 2025
    4.9
    Medium

    CVE-2025-3577

    Last Modified: 23 Jun 2025

    **UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories by sending a crafted HTTP request to an affected device.

    Published: 22 Apr 2025