CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2025-25155

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in efreja Music Sheet Viewer music-sheet-viewer allows Path Traversal.This issue affects Music Sheet Viewer: from n/a through <= 4.1.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25154

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in scweber Custom Comment Notifications custom-comment-notifications allows Stored XSS.This issue affects Custom Comment Notifications: from n/a through <= 1.0.8.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25159

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robert_kolatzek WP doodlez wpdoodlez allows Stored XSS.This issue affects WP doodlez: from n/a through <= 1.0.10.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25160

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Mark Barnes Style Tweaker style-tweaker allows Stored XSS.This issue affects Style Tweaker: from n/a through <= 0.11.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25152

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in LukaszWiecek Smart DoFollow smart-dofollow allows Stored XSS.This issue affects Smart DoFollow: from n/a through <= 1.0.2.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25156

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Stanko Metodiev Quote Comments quote-comments allows Stored XSS.This issue affects Quote Comments: from n/a through <= 3.0.0.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25153

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in djjmz Simple Auto Tag simple-auto-tag allows Stored XSS.This issue affects Simple Auto Tag: from n/a through <= 1.1.

    Published: 7 Feb 2025
    8.5
    High

    CVE-2025-25151

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing ulisting allows SQL Injection.This issue affects uListing: from n/a through <= 2.1.6.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25144

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in theasys Theasys theasys allows Stored XSS.This issue affects Theasys: from n/a through <= 1.0.1.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25149

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Danillo Nunes Login-box login-box allows Stored XSS.This issue affects Login-box: from n/a through <= 2.0.4.

    Published: 7 Feb 2025
    7.5
    High

    CVE-2025-25141

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zankover Fami Sales Popup fami-sales-popup allows PHP Local File Inclusion.This issue affects Fami Sales Popup: from n/a through <= 2.0.0.

    Published: 7 Feb 2025
    4.3
    Medium

    CVE-2025-25143

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ibasit GlobalQuran globalquran allows Cross Site Request Forgery.This issue affects GlobalQuran: from n/a through <= 1.0.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25147

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Phillip.Gooch Auto SEO auto-seo allows Stored XSS.This issue affects Auto SEO: from n/a through <= 2.5.6.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25138

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Rishi On Page SEO + Whatsapp Chat Button ops-robots-txt allows Stored XSS.This issue affects On Page SEO + Whatsapp Chat Button: from n/a through <= 2.0.0.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25135

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Victor Barkalov Custom Links On Admin Dashboard Toolbar customize-wpadmin allows Stored XSS.This issue affects Custom Links On Admin Dashboard Toolbar: from n/a through <= 3.3.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25148

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ElbowRobo Read More Copy Link read-more-copy-link allows Stored XSS.This issue affects Read More Copy Link: from n/a through <= 1.0.2.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25140

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Scriptonite Simple User Profile simple-user-profile allows Stored XSS.This issue affects Simple User Profile: from n/a through <= 1.9.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25139

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Cynob IT Consultancy WP Custom Post RSS Feed wp-custom-post-rss-feed allows Stored XSS.This issue affects WP Custom Post RSS Feed: from n/a through <= 1.0.0.

    Published: 7 Feb 2025
    5.4
    Medium

    CVE-2025-25145

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in jordan.hatch Infusionsoft Analytics infusionsoft-web-tracker allows Cross Site Request Forgery.This issue affects Infusionsoft Analytics: from n/a through <= 2.0.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25136

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shujahat21 Optimate Ads optimate-ads allows Stored XSS.This issue affects Optimate Ads: from n/a through <= 1.0.3.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25126

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in zmseo ZMSEO zmseo allows Stored XSS.This issue affects ZMSEO: from n/a through <= 1.14.1.

    Published: 7 Feb 2025
    4.3
    Medium

    CVE-2025-25146

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in saleandro Songkick Concerts and Festivals songkick-concerts-and-festivals allows Cross Site Request Forgery.This issue affects Songkick Concerts and Festivals: from n/a through <= 0.9.7.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25128

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in orlandolac Facilita Form Tracker facilita-form-tracker allows Stored XSS.This issue affects Facilita Form Tracker: from n/a through <= 1.0.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25123

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in xdark Easy Related Posts easy-related-posts allows Stored XSS.This issue affects Easy Related Posts: from n/a through <= 2.0.2.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25125

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CyrilG Fyrebox Quizzes fyrebox-shortcode allows Stored XSS.This issue affects Fyrebox Quizzes: from n/a through <= 3.1.

    Published: 7 Feb 2025
    7.6
    High

    CVE-2025-25116

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sudipto Link to URL / Post link-to-url-post allows Blind SQL Injection.This issue affects Link to URL / Post: from n/a through <= 1.3.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25117

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Polonski Smart Countdown FX smart-countdown-fx allows Stored XSS.This issue affects Smart Countdown FX: from n/a through <= 1.5.5.

    Published: 7 Feb 2025
    4.3
    Medium

    CVE-2025-25120

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Melodic Media Slide Banners slide-banners allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slide Banners: from n/a through <= 1.3.

    Published: 7 Feb 2025
    4.3
    Medium

    CVE-2025-25103

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in bnielsen Indeed API indeed-api allows Cross Site Request Forgery.This issue affects Indeed API: from n/a through <= 0.5.

    Published: 7 Feb 2025
    5.9
    Medium

    CVE-2025-25105

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in coffeestudios Pop Up popup-seo-optimized allows Stored XSS.This issue affects Pop Up: from n/a through <= 0.1.

    Published: 7 Feb 2025
    9.6
    Critical

    CVE-2025-25101

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery.This issue affects Munk Sites: from n/a through <= 1.0.7.

    Published: 7 Feb 2025
    9.6
    Critical

    CVE-2025-25107

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites onestore-sites allows Cross Site Request Forgery.This issue affects OneStore Sites: from n/a through <= 0.1.1.

    Published: 7 Feb 2025
    9.6
    Critical

    CVE-2025-25106

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP starter-templates allows Cross Site Request Forgery.This issue affects Starter Templates by FancyWP: from n/a through <= 2.0.0.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25097

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kwiliarty External Video For Everybody external-video-for-everybody allows Stored XSS.This issue affects External Video For Everybody: from n/a through <= 2.1.1.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25088

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in blackus3r WP Keyword Monitor wp-keyword-monitor allows Cross Site Request Forgery.This issue affects WP Keyword Monitor: from n/a through <= 1.0.5.

    Published: 7 Feb 2025
    5.4
    Medium

    CVE-2025-25110

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Metagauss Event Kikfyre kikfyre-events-calendar-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Kikfyre: from n/a through <= 2.1.8.

    Published: 7 Feb 2025
    5.4
    Medium

    CVE-2025-25111

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Cross Site Request Forgery.This issue affects WP Spell Check: from n/a through <= 9.21.

    Published: 7 Feb 2025
    4.2
    Medium

    CVE-2025-25081

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in DeannaS Embed RSS embed-rss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Embed RSS: from n/a through <= 3.1.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25104

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in mraliende URL-Preview-Box good-url-preview-box allows Cross Site Request Forgery.This issue affects URL-Preview-Box: from n/a through <= 1.20.

    Published: 7 Feb 2025
    6.1
    Medium

    CVE-2025-25093

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in paulswarthout Child Themes Helper child-themes-helper allows Path Traversal.This issue affects Child Themes Helper: from n/a through <= 2.2.7.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25095

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reverbnationdev ReverbNation Widgets reverbnation-widgets allows Stored XSS.This issue affects ReverbNation Widgets: from n/a through <= 2.1.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25096

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in titusbicknell RSS in Page rss-in-page allows Stored XSS.This issue affects RSS in Page: from n/a through <= 2.9.1.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25085

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matt_mcbrien WP SimpleWeather wp-simpleweather allows Stored XSS.This issue affects WP SimpleWeather: from n/a through <= 0.2.5.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25071

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in topplugins Vignette Ads vignete-ads allows Stored XSS.This issue affects Vignette Ads: from n/a through <= 0.2.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25094

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amitythemes.com Breaking News Ticker breaking-news-ticker allows Stored XSS.This issue affects Breaking News Ticker: from n/a through <= 2.4.4.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25080

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gubbigubbi Kona Gallery Block kona-instagram-feed-for-gutenberg allows Stored XSS.This issue affects Kona Gallery Block: from n/a through <= 1.7.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25077

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dugbug Easy Chart Builder for WordPress easy-chart-builder allows Stored XSS.This issue affects Easy Chart Builder for WordPress: from n/a through <= 1.3.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25075

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Show notice or message on admin area show-notice-or-message-on-admin-area allows Stored XSS.This issue affects Show notice or message on admin area: from n/a through <= 2.0.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25078

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrew Norcross Google Earth Embed google-earth-tours allows Stored XSS.This issue affects Google Earth Embed: from n/a through <= 1.0.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25074

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Nirmal Kumar Ram WP Social Stream wp-social-stream allows Stored XSS.This issue affects WP Social Stream: from n/a through <= 1.1.

    Published: 7 Feb 2025