CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2025-31377

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Asaquzzaman mishu Woo Product Feed For Marketing Channels woocommerce-to-google-merchant-center allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Product Feed For Marketing Channels: from n/a through <= 1.9.0.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31382

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in theode Language Field language-field allows Stored XSS.This issue affects Language Field: from n/a through <= 0.9.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31388

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in doa The World the-world allows Stored XSS.This issue affects The World: from n/a through <= 0.4.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31390

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in bdoga Social Crowd social-crowd allows Stored XSS.This issue affects Social Crowd: from n/a through <= 0.9.6.1.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31391

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in regen Script Compressor script-compressor allows Stored XSS.This issue affects Script Compressor: from n/a through <= 1.7.1.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31392

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Shameem Reza Smart Product Gallery Slider smart-product-gallery-slider allows Cross Site Request Forgery.This issue affects Smart Product Gallery Slider: from n/a through <= 1.0.4.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31393

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in vfvalent Social Bookmarking RELOADED social-bookmarking-reloaded allows Stored XSS.This issue affects Social Bookmarking RELOADED: from n/a through <= 3.18.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31394

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey (trepmal) More Mime Type Filters more-mime-type-filters allows Stored XSS.This issue affects More Mime Type Filters: from n/a through <= 0.3.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31395

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in a.ankit Easy Custom CSS easy-custom-css allows Stored XSS.This issue affects Easy Custom CSS: from n/a through <= 1.0.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31399

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Chandan Garg CG Scroll To Top cg-scroll-to-top allows Stored XSS.This issue affects CG Scroll To Top: from n/a through <= 3.5.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31400

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in icyleaf WS Audio Player ws-audio-player allows Stored XSS.This issue affects WS Audio Player: from n/a through <= 1.1.8.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31401

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in mmetrodw MMX – Make Me Christmas mmx-make-me-christmas allows Stored XSS.This issue affects MMX – Make Me Christmas: from n/a through <= 1.0.0.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31402

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in NewsBoard Plugin NewsBoard Post and RSS Scroller newsboard allows Stored XSS.This issue affects NewsBoard Post and RSS Scroller: from n/a through <= 1.2.12.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-31404

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Wladyslaw Madejczyk AF Tell a Friend af-tell-a-friend allows Stored XSS.This issue affects AF Tell a Friend: from n/a through <= 1.4.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32476

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in blueinstyle Advanced Tag Lists advanced-tag-list allows Stored XSS.This issue affects Advanced Tag Lists: from n/a through <= 1.2.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32477

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Jordi Salord WP-Easy Menu wp-easy-menu allows Stored XSS.This issue affects WP-Easy Menu: from n/a through <= 0.41.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32478

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Mario Aguiar WP SexyLightBox wp-sexylightbox allows Stored XSS.This issue affects WP SexyLightBox: from n/a through <= 0.5.3.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32479

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ab-tools Flags Widget flags-widget allows Stored XSS.This issue affects Flags Widget: from n/a through <= 1.0.7.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32480

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in dalziel Windows Live Writer windows-live-writer allows Stored XSS.This issue affects Windows Live Writer: from n/a through <= 0.1.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32481

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ninotheme Nino Social Connect nino-social-connect allows Stored XSS.This issue affects Nino Social Connect: from n/a through <= 2.0.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32482

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in quanganhdo Custom Smilies custom-smilies allows Stored XSS.This issue affects Custom Smilies: from n/a through <= 1.2.

    Published: 9 Apr 2025
    5.9
    Medium

    CVE-2025-32483

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Salisbury Request Call Back request-call-back allows Stored XSS.This issue affects Request Call Back: from n/a through <= 1.4.1.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32484

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WP-Planification wp-planification allows Stored XSS.This issue affects WP-Planification: from n/a through <= 2.3.1.

    Published: 9 Apr 2025
    4.3
    Medium

    CVE-2025-32485

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Bjoern WP Performance Pack wp-performance-pack allows Cross Site Request Forgery.This issue affects WP Performance Pack: from n/a through <= 2.5.4.

    Published: 9 Apr 2025
    4.9
    Medium

    CVE-2025-32487

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Joe Waymark waymark allows Server Side Request Forgery.This issue affects Waymark: from n/a through <= 1.5.2.

    Published: 9 Apr 2025
    5.9
    Medium

    CVE-2025-32488

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in آریا وردپرس Aria Font aria-font allows Stored XSS.This issue affects Aria Font: from n/a through <= 1.4.

    Published: 9 Apr 2025
    5.9
    Medium

    CVE-2025-32489

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Wetterwarner wetterwarner allows Stored XSS.This issue affects Wetterwarner: from n/a through <= 2.7.3.

    Published: 9 Apr 2025
    5.9
    Medium

    CVE-2025-32492

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eliot Akira Admin Menu Post List admin-menu-post-list allows Stored XSS.This issue affects Admin Menu Post List: from n/a through <= 2.0.7.

    Published: 9 Apr 2025
    5.9
    Medium

    CVE-2025-32493

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes BP Social Connect bp-social-connect allows Stored XSS.This issue affects BP Social Connect: from n/a through <= 1.6.2.

    Published: 9 Apr 2025
    4.3
    Medium

    CVE-2025-32494

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in bozdoz reCAPTCHA Jetpack recaptcha-jetpack allows Cross Site Request Forgery.This issue affects reCAPTCHA Jetpack: from n/a through <= 0.2.2.

    Published: 9 Apr 2025
    6.5
    Medium

    CVE-2025-32495

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Waymark waymark allows Stored XSS.This issue affects Waymark: from n/a through <= 1.5.3.

    Published: 9 Apr 2025
    9.6
    Critical

    CVE-2025-32496

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web Shell to a Web Server.This issue affects Ultra Demo Importer: from n/a through <= 1.0.5.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32497

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in squiter Spoiler Block spoiler-block allows Stored XSS.This issue affects Spoiler Block: from n/a through <= 1.7.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32498

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in oleglark VKontakte Cross-Post vkontakte-cross-post allows Stored XSS.This issue affects VKontakte Cross-Post: from n/a through <= 0.3.2.

    Published: 9 Apr 2025
    6.5
    Medium

    CVE-2025-32499

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Logo Showcase Ultimate logo-showcase-ultimate allows PHP Local File Inclusion.This issue affects Logo Showcase Ultimate: from n/a through <= 1.4.4.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32500

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sudavar Codescar Radio Widget codescar-radio-widget allows Stored XSS.This issue affects Codescar Radio Widget: from n/a through <= 0.4.2.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32501

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in dimafreund Rentsyst rentsyst allows Stored XSS.This issue affects Rentsyst: from n/a through <= 2.0.92.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32502

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in lemmentwickler ePaper Lister for Yumpu magazine-lister-for-yumpu allows Stored XSS.This issue affects ePaper Lister for Yumpu: from n/a through <= 1.4.0.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32503

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Conti Link Shield link-shield allows Stored XSS.This issue affects Link Shield: from n/a through <= 0.5.4.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32505

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in SCAND MultiMailer scand-multi-mailer allows Stored XSS.This issue affects MultiMailer: from n/a through <= 1.0.3.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32518

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in hossainawlad ALD Login Page ald-login-page allows Stored XSS.This issue affects ALD Login Page: from n/a through <= 1.1.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32543

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hivedigital Canonical Attachments canonical-attachments allows Reflected XSS.This issue affects Canonical Attachments: from n/a through <= 1.8.

    Published: 9 Apr 2025
    8.2
    High

    CVE-2025-32547

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in gtlwpdev All push notification for WP all-push-notification allows Blind SQL Injection.This issue affects All push notification for WP: from n/a through <= 1.5.3.

    Published: 9 Apr 2025
    7.2
    High

    CVE-2025-32550

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect Plugin allows SQL Injection. This issue affects Click & Pledge Connect Plugin: from 2.24080000 through WP6.6.1.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32555

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Edamam SEO, Nutrition and Print for Recipes by Edamam seo-nutrition-and-print-for-recipes-by-edamam allows Stored XSS.This issue affects SEO, Nutrition and Print for Recipes by Edamam: from n/a through <= 3.3.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32556

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sandor Kovacs Simple Post Meta Manager simple-post-meta-manager allows Reflected XSS.This issue affects Simple Post Meta Manager: from n/a through <= 1.0.9.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32559

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in REVE Chat REVE Chat revechat allows Stored XSS.This issue affects REVE Chat: from n/a through <= 6.4.4.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32563

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in dangrossman WP Calais Auto Tagger calais-auto-tagger allows Cross Site Request Forgery.This issue affects WP Calais Auto Tagger: from n/a through <= 2.0.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32570

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ChillPay ChillPay WooCommerce chillpay-payment-gateway allows Stored XSS.This issue affects ChillPay WooCommerce: from n/a through <= 2.5.3.

    Published: 9 Apr 2025
    7.1
    High

    CVE-2025-32575

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB wp-w3all-phpbb-integration allows Reflected XSS.This issue affects WP w3all phpBB: from n/a through <= 2.9.9.

    Published: 9 Apr 2025