CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2025-31831

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Team AtomChat AtomChat atomchat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AtomChat: from n/a through <= 1.1.7.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31830

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Uriahs Victor Printus printus-cloud-printing-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Printus: from n/a through <= 1.2.6.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31829

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred ShopCred shopcred allows DOM-Based XSS.This issue affects ShopCred: from n/a through <= 1.3.0.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31828

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n/a through <= 1.4.2.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31826

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods ni-woocommerce-cost-of-goods allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ni WooCommerce Cost Of Goods: from n/a through <= 3.2.8.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31824

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Wombat Plugins WP Optin Wheel wp-optin-wheel allows Server Side Request Forgery.This issue affects WP Optin Wheel: from n/a through <= 1.4.7.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31823

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpoperations WPoperation Elementor Addons wpop-elementor-addons allows Stored XSS.This issue affects WPoperation Elementor Addons: from n/a through <= 1.1.9.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31822

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Ashish Ajani WP Simple HTML Sitemap wp-simple-html-sitemap allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Simple HTML Sitemap: from n/a through <= 3.5.

    Published: 1 Apr 2025
    4.7
    Medium

    CVE-2025-31821

    Last Modified: 15 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integration of Zoho CRM and Contact Form 7 allows Phishing. This issue affects Integration of Zoho CRM and Contact Form 7: from n/a through 1.0.6.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31820

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.4.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31818

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ContentBot.ai ContentBot AI Writer content-bot allows Stored XSS.This issue affects ContentBot AI Writer: from n/a through <= 1.2.4.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31817

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPWheels BlockWheels blockwheels allows DOM-Based XSS.This issue affects BlockWheels: from n/a through <= 1.0.2.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31816

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in pietro Mobile App Canvas mobile-app allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobile App Canvas: from n/a through <= 3.8.2.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31815

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred Design Blocks exclusive-blocks allows Stored XSS.This issue affects Design Blocks: from n/a through <= 1.2.5.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31814

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in OwnerRez OwnerRez API ownerrez allows Cross Site Request Forgery.This issue affects OwnerRez API: from n/a through <= 1.2.0.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31813

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Website366.com WPSHARE247 Elementor Addons wpshare247-elementor-addons allows Stored XSS.This issue affects WPSHARE247 Elementor Addons: from n/a through <= 2.5.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31812

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomas BuddyPress Members Only buddypress-members-only allows Stored XSS.This issue affects BuddyPress Members Only: from n/a through <= 3.5.3.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31811

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtreeme Planyo online reservation system planyo-online-reservation-system allows Stored XSS.This issue affects Planyo online reservation system: from n/a through <= 3.1.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31810

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in PickPlugins Question Answer question-answer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Question Answer: from n/a through <= 1.2.73.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31809

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Labinator Labinator Content Types Duplicator labinator-content-types-duplicator allows Cross Site Request Forgery.This issue affects Labinator Content Types Duplicator: from n/a through <= 1.1.3.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31808

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in IT Path Solutions SCSS WP Editor scss-wp-editor allows Cross Site Request Forgery.This issue affects SCSS WP Editor: from n/a through <= 1.2.1.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31807

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CloudRedux Product Notices for WooCommerce product-notices-for-woocommerce allows Cross Site Request Forgery.This issue affects Product Notices for WooCommerce: from n/a through <= 1.3.4.

    Published: 1 Apr 2025
    5.9
    Medium

    CVE-2025-31806

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uSystems Webling webling allows Stored XSS.This issue affects Webling: from n/a through <= 3.9.0.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31805

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal Gutena Kit – Gutenberg Blocks and Templates gutena-kit allows Stored XSS.This issue affects Gutena Kit – Gutenberg Blocks and Templates: from n/a through <= 2.0.7.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31804

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DraftPress Team Follow Us Badges wpsite-follow-us-badges allows Stored XSS.This issue affects Follow Us Badges: from n/a through <= 3.1.11.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31803

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Neteuro Turisbook Booking System turisbook-booking-system allows Stored XSS.This issue affects Turisbook Booking System: from n/a through <= 1.3.8.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31802

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Shiptimize Shiptimize for WooCommerce shiptimize-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shiptimize for WooCommerce: from n/a through <= 3.1.86.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31801

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Time Zone Clocks mx-time-zone-clocks allows Reflected XSS.This issue affects MX Time Zone Clocks: from n/a through <= 5.1.1.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31799

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in publitio Publitio publitio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Publitio: from n/a through <= 2.1.8.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31798

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in publitio Publitio publitio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Publitio: from n/a through <= 2.1.8.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31797

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Stored XSS.This issue affects Sprout Clients: from n/a through <= 3.2.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31796

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in TheInnovs ElementsCSS Addons for Elementor css-for-elementor allows Server Side Request Forgery.This issue affects ElementsCSS Addons for Elementor: from n/a through <= 1.0.8.9.

    Published: 1 Apr 2025
    5.9
    Medium

    CVE-2025-31793

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms piotnetforms allows Stored XSS.This issue affects Piotnet Forms: from n/a through <= 1.0.30.

    Published: 1 Apr 2025
    5.9
    Medium

    CVE-2025-31792

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms piotnetforms allows Stored XSS.This issue affects Piotnet Forms: from n/a through <= 1.0.30.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31791

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Oliver Boyers Pin Generator pin-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pin Generator: from n/a through <= 2.0.0.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31790

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Binsaifullah Posten posten-post-blocks allows DOM-Based XSS.This issue affects Posten: from n/a through <= 0.0.1.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31788

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Retrieve Embedded Sensitive Data.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through <= 1.3.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31787

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in AudioTheme Cue cue allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cue: from n/a through <= 2.4.4.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31786

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Travis Simple Icons simple-icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Icons: from n/a through <= 2.8.4.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31785

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Clearbit Clearbit Reveal clearbit allows Cross Site Request Forgery.This issue affects Clearbit Reveal: from n/a through <= 1.0.6.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31784

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Rudy Susanto Embed Extended embed-extended allows Cross Site Request Forgery.This issue affects Embed Extended: from n/a through <= 1.4.0.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31783

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leartes.NET Leartes TRY Exchange Rates leartes-try-exchange-rates allows Stored XSS.This issue affects Leartes TRY Exchange Rates: from n/a through <= 2.1.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31782

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in pupunzi mb.YTPlayer wpmbytplayer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects mb.YTPlayer: from n/a through <= 3.3.8.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31781

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ahmadshyk Gift Cards for WooCommerce woo-giftcards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gift Cards for WooCommerce: from n/a through <= 1.5.8.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31780

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Andy Stratton Append Content append-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Append Content: from n/a through <= 2.1.1.

    Published: 1 Apr 2025
    5.4
    Medium

    CVE-2025-31779

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Jonathan Daggerhart Query Wrangler query-wrangler allows Cross Site Request Forgery.This issue affects Query Wrangler: from n/a through <= 1.5.54.

    Published: 1 Apr 2025
    6.5
    Medium

    CVE-2025-31778

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in raphaelheide Donate Me donate-me allows Reflected XSS.This issue affects Donate Me: from n/a through <= 1.2.5.

    Published: 1 Apr 2025
    5.3
    Medium

    CVE-2025-31777

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in BeastThemes Clockinator Lite clockify-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clockinator Lite: from n/a through <= 1.0.9.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31776

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Aphotrax Uptime Robot Plugin for WordPress uptime-robot-monitor allows Cross Site Request Forgery.This issue affects Uptime Robot Plugin for WordPress: from n/a through <= 2.3.

    Published: 1 Apr 2025
    4.3
    Medium

    CVE-2025-31775

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Smackcoders Inc., Google SEO Pressor Snippet google-seo-author-snippets allows Cross Site Request Forgery.This issue affects Google SEO Pressor Snippet: from n/a through <= 2.0.

    Published: 1 Apr 2025