Latest CVE Feed
-
4.3
MEDIUMCVE-2025-49077
Cross-Site Request Forgery (CSRF) vulnerability in ThemeHigh Dynamic Pricing and Discount Rules allows Cross Site Request Forgery.This issue affects Dynamic Pricing and Discount Rules: from n/a through 2.2.9.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2023-25995
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in choicehomemortgage AI Mortgage Calculator allows PHP Local File Inclusion. This issue affects AI Mortgage Calculator: from n/a through... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Path Traversal
-
7.6
HIGHCVE-2023-26003
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vipul Jariwala WP Post Corrector allows SQL Injection. This issue affects WP Post Corrector: from n/a through 1.0.2.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-24778
Missing Authorization vulnerability in De paragon No Spam At All allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects No Spam At All: from n/a through 1.3.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-28952
Cross-Site Request Forgery (CSRF) vulnerability in Jonathan Lau CubePoints allows Cross Site Request Forgery. This issue affects CubePoints: from n/a through 3.2.1.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2025-28966
Cross-Site Request Forgery (CSRF) vulnerability in dilemma123 Recent Posts Slider Responsive allows Stored XSS. This issue affects Recent Posts Slider Responsive: from n/a through 1.0.1.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-28984
Cross-Site Request Forgery (CSRF) vulnerability in storepro Subscription Renewal Reminders for WooCommerce allows Cross Site Request Forgery. This issue affects Subscription Renewal Reminders for WooCommerce: from n/a through 1.3.7.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-28994
Missing Authorization vulnerability in viralloops Viral Loops WP Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Viral Loops WP Integration: from n/a through 3.8.1.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
4.9
MEDIUMCVE-2025-29008
Server-Side Request Forgery (SSRF) vulnerability in ShawonPro SocialMark allows Server Side Request Forgery. This issue affects SocialMark: from n/a through 2.0.7.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Server-Side Request Forgery
-
5.9
MEDIUMCVE-2025-30627
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in regolithsjk Elegant Visitor Counter allows Stored XSS. This issue affects Elegant Visitor Counter: from n/a through 3.1.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2025-30637
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro allows Stored XSS. This issue affects Booking Ultra Pro: from n/a through 1.1.20.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-30935
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NickDuncan Contact Form allows DOM-Based XSS. This issue affects Contact Form: from n/a through 2.0.12.... Read more
Affected Products : contact_form- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-30946
Cross-Site Request Forgery (CSRF) vulnerability in Michael Cannon Custom Bulk/Quick Edit allows Cross Site Request Forgery. This issue affects Custom Bulk/Quick Edit: from n/a through 1.6.10.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-30952
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdive Nexa Blocks allows Stored XSS. This issue affects Nexa Blocks: from n/a through 1.1.0.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-30968
Cross-Site Request Forgery (CSRF) vulnerability in jokerbr313 Advanced Post List allows Cross Site Request Forgery. This issue affects Advanced Post List: from n/a through 0.5.6.2.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-30994
Cross-Site Request Forgery (CSRF) vulnerability in Emraan Cheema CubeWP – All-in-One Dynamic Content Framework allows Cross Site Request Forgery. This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.23.... Read more
Affected Products : cubewp- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-49073
Deserialization of Untrusted Data vulnerability in Axiomthemes Sweet Dessert allows Object Injection.This issue affects Sweet Dessert: from n/a before 1.1.13.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-49239
Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce allows Cross Site Request Forgery. This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 5.5.0.... Read more
Affected Products : print_invoice_\&_delivery_notes_for_woocommerce- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-49246
Missing Authorization vulnerability in cmoreira Testimonials Showcase allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Testimonials Showcase: from n/a through 1.9.16.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
8.2
HIGHCVE-2025-28986
Cross-Site Request Forgery (CSRF) vulnerability in Webaholicson Epicwin Plugin allows SQL Injection. This issue affects Epicwin Plugin: from n/a through 1.5.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery