CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-31884

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP CMS Ninja Norse Rune Oracle Plugin norse-runes-oracle allows Stored XSS.This issue affects Norse Rune Oracle Plugin: from n/a through <= 1.4.3.

    Published: 1 Apr 2025
    5.9
    Medium

    CVE-2025-31883

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Stored XSS.This issue affects WebinarPress: from n/a through <= 1.33.28.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31882

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarPress: from n/a through <= 1.33.28.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31881

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Stylemix Pearl pearl-header-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pearl: from n/a through <= 1.3.9.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31880

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Stylemix Pearl pearl-header-builder allows Cross Site Request Forgery.This issue affects Pearl: from n/a through <= 1.3.9.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31879

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-barcodes-into-product-pages-and-orders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Barcode Generator for WooCommerce: from n/a through <= 2.0.4.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31878

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator upc-ean-barcode-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UPC/EAN/GTIN Code Generator: from n/a through <= 2.0.2.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31877

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.8.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31875

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluginic FancyPost post-block allows DOM-Based XSS.This issue affects FancyPost: from n/a through <= 6.0.1.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31874

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay WebberZone Snippetz add-to-all allows Stored XSS.This issue affects WebberZone Snippetz: from n/a through <= 2.1.1.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31873

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sheetdb SheetDB sheetdb allows Stored XSS.This issue affects SheetDB: from n/a through <= 1.3.4.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31872

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Clone any post type: from n/a through <= 3.6.

    Published: 1 Apr 2025
    4.7
    Medium

    CVE-2025-31871

    Last Modified: 23 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Phishing.This issue affects WP Clone any post type: from n/a through <= 3.6.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31870

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in EXEIdeas International WP AutoKeyword wp-autokeyword allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP AutoKeyword: from n/a through <= 1.0.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31869

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor black-widgets allows Stored XSS.This issue affects Black Widgets For Elementor: from n/a through <= 1.3.9.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31868

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in JoomSky JS Job Manager js-jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Job Manager: from n/a through <= 2.0.2.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31867

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager js-jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Job Manager: from n/a through <= 2.0.2.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31866

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Ship Depot ShipDepot for WooCommerce ship-depot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShipDepot for WooCommerce: from n/a through <= 1.2.19.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31865

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in CartBoss CartBoss cartboss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartBoss: from n/a through <= 4.1.2.

    Published: 1 Apr 2025
    5.9
    Medium

    CVE-2025-31864

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Out the Box Beam me up Scotty beam-me-up-scotty allows Stored XSS.This issue affects Beam me up Scotty: from n/a through <= 1.0.23.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31863

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in inspry Agency Toolkit agency-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Agency Toolkit: from n/a through <= 1.0.24.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31862

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.61.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31861

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPOrbit Support Perfect Font Awesome Integration perfect-font-awesome-integration allows Stored XSS.This issue affects Perfect Font Awesome Integration: from n/a through <= 2.3.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31860

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter: from n/a through <= 2.5.8.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31859

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Feedbucket Feedbucket – Website Feedback Tool feedbucket allows Cross Site Request Forgery.This issue affects Feedbucket – Website Feedback Tool: from n/a through <= 1.0.6.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31857

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Directorist AddonsKit for Elementor addonskit-for-elementor allows Stored XSS.This issue affects Directorist AddonsKit for Elementor: from n/a through <= 1.1.6.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31856

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in brainvireinfo Export All Post Meta export-all-post-meta allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export All Post Meta: from n/a through <= 1.2.1.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31855

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softnwords SMM API smm-api allows Stored XSS.This issue affects SMM API: from n/a through <= 6.0.31.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31854

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Sharaz Shahid Simple Sticky Add To Cart For WooCommerce sticky-add-to-cart-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Sticky Add To Cart For WooCommerce: from n/a through <= 1.4.9.

    Published: 1 Apr 2025
    5.9
    Medium

    CVE-2025-31853

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget Popup smartarget-popup allows Stored XSS.This issue affects Smartarget Popup: from n/a through <= 1.5.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31852

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in N-Media Bulk Product Sync sync-wc-google allows Cross Site Request Forgery.This issue affects Bulk Product Sync: from n/a through <= 8.6.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31851

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in markkinchin Beds24 Online Booking beds24-online-booking allows Stored XSS.This issue affects Beds24 Online Booking: from n/a through <= 2.0.27.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31850

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder pdf-generator-addon-for-elementor-page-builder allows Stored XSS.This issue affects PDF Generator Addon for Elementor Page Builder: from n/a through <= 2.1.0.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31849

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fbtemplates Nemesis All-in-One nemesis-all-in-one allows Stored XSS.This issue affects Nemesis All-in-One: from n/a through <= 1.1.3.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31848

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPFactory Adverts adverts-click-tracker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Adverts: from n/a through <= 1.4.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31847

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelooks mFolio Lite mfolio-lite allows DOM-Based XSS.This issue affects mFolio Lite: from n/a through <= 1.2.3.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31846

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.18.7.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31845

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Rohit Choudhary Theme Duplicator theme-duplicator allows Cross Site Request Forgery.This issue affects Theme Duplicator: from n/a through <= 1.1.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31844

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Blocks magical-blocks allows Stored XSS.This issue affects Magical Blocks: from n/a through <= 1.0.12.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31843

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Wilson OpenAI Tools for WordPress & WooCommerce openai-tools-for-wp-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OpenAI Tools for WordPress & WooCommerce: from n/a through <= 2.2.1.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31842

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Retrieve Embedded Sensitive Data.This issue affects Viral Loops WP Integration: from n/a through <= 3.4.0.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31840

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in digireturn Simple Fixed Notice dn-cookie-notice allows Cross Site Request Forgery.This issue affects Simple Fixed Notice: from n/a through <= 1.6.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31839

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in digireturn DN Footer Contacts dn-footer-contacts allows Cross Site Request Forgery.This issue affects DN Footer Contacts: from n/a through <= 1.8.1.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31838

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eventbee Eventbee RSVP Widget eventbee-rsvp-widget allows DOM-Based XSS.This issue affects Eventbee RSVP Widget: from n/a through <= 1.0.

    Published: 1 Apr 2025
    5.9
    Medium

    CVE-2025-31837

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus WP Proposals allows Stored XSS. This issue affects WP Proposals: from n/a through 2.3.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31836

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in matthewrubin Review Manager review-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Review Manager: from n/a through <= 2.5.0.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31835

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brice Capobianco WP Plugin Info Card wp-plugin-info-card allows DOM-Based XSS.This issue affects WP Plugin Info Card: from n/a through <= 5.3.0.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31834

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in themeglow JobBoard Job listing job-board-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoard Job listing: from n/a through <= 1.2.8.

    Published: 1 Apr 2025
    4.9
    Medium

    CVE-2025-31833

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in themeglow JobBoard Job listing job-board-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoard Job listing: from n/a through <= 1.2.8.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31832

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee ACF City Selector acf-city-selector allows Retrieve Embedded Sensitive Data.This issue affects ACF City Selector: from n/a through <= 1.17.0.

    Published: 1 Apr 2025