Wpbeginner

    Dashboard / Vendors

    Products: 5
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-5275

    Charitable <= 1.8.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Privacy Settings

    Last Modified: Apr 22, 2026
    Published: Jun 26, 2025

    CVE-2025-4577

    Smash Balloon Custom Facebook Feed <= 4.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color` Attribute

    Last Modified: Apr 20, 2026
    Published: Jun 10, 2025

    CVE-2024-10878

    Sugar Calendar (Lite) <= 3.3.0 - Reflected Cross-Site Scripting

    Last Modified: Apr 08, 2026
    Published: Nov 26, 2024

    CVE-2024-10045

    Transients Manager <= 2.0.6 - Cross-Site Request Forgery

    Last Modified: Apr 08, 2026
    Published: Oct 23, 2024

    CVE-2015-5528

    Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Social Bar plugin before 1.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the items[] parameter in an fsb_save_order action to wp-admin/admin-ajax.php.

    Last Modified: Apr 12, 2025
    Published: Jul 16, 2015
    Items Per Page