Latest CVE Feed
-
8.8
HIGHCVE-2025-24742
Cross-Site Request Forgery (CSRF) vulnerability in WP Go Maps (formerly WP Google Maps) WP Go Maps. This issue affects WP Go Maps: from n/a through 9.0.40.... Read more
Affected Products : wp_go_maps- Published: Jan. 27, 2025
- Modified: Feb. 11, 2025
-
6.1
MEDIUMCVE-2025-24741
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in KB Support KB Support. This issue affects KB Support: from n/a through 1.6.7.... Read more
- Published: Jan. 27, 2025
- Modified: Feb. 10, 2025
-
4.7
MEDIUMCVE-2025-24740
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ThimPress LearnPress. This issue affects LearnPress: from n/a through 4.2.7.1.... Read more
Affected Products : learnpress- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
8.8
HIGHCVE-2025-24734
Missing Authorization vulnerability in CodeSolz Better Find and Replace allows Privilege Escalation. This issue affects Better Find and Replace: from n/a through 1.6.7.... Read more
Affected Products : better_find_and_replace- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
7.1
HIGHCVE-2025-24708
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms allows Reflected XSS. This issue affects WP Dynamics CRM for... Read more
Affected Products :- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
5.9
MEDIUMCVE-2025-24689
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in codection Import and export users and customers allows Retrieve Embedded Sensitive Data. This issue affects Import and export users and customers: from n/a th... Read more
Affected Products : import_and_export_users_and_customers- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
7.1
HIGHCVE-2025-24680
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WpMultiStoreLocator WP Multi Store Locator allows Reflected XSS. This issue affects WP Multi Store Locator: from n/a through 2.4.7.... Read more
Affected Products : wp_multi_store_locator- Published: Jan. 27, 2025
- Modified: Feb. 25, 2025
-
9.8
CRITICALCVE-2025-24671
Deserialization of Untrusted Data vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Object Injection. This issue affects Save as PDF plugin by Pdfcrowd: from n/a through 4.4.0.... Read more
Affected Products : save_as_pdf- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
9.3
CRITICALCVE-2025-24667
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology Small Package Quotes – Worldwide Express Edition allows SQL Injection. This issue affects Small Package Quotes – Worldwide Express Edi... Read more
Affected Products : small_package_quotes- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
9.3
CRITICALCVE-2025-24665
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology Small Package Quotes – Unishippers Edition allows SQL Injection. This issue affects Small Package Quotes – Unishippers Edition: from n... Read more
Affected Products : small_package_quotes- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
5.3
MEDIUMCVE-2025-24662
Missing Authorization vulnerability in LearnDash LearnDash LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnDash LMS: from n/a through 4.20.0.1.... Read more
Affected Products : learndash- Published: Jan. 27, 2025
- Modified: Mar. 27, 2025
-
4.3
MEDIUMCVE-2025-24653
Missing Authorization vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.1.1.... Read more
Affected Products :- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
5.3
MEDIUMCVE-2025-24628
Authentication Bypass by Spoofing vulnerability in BestWebSoft Google Captcha allows Identity Spoofing. This issue affects Google Captcha: from n/a through 1.78.... Read more
Affected Products :- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
7.1
HIGHCVE-2025-24626
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Music Store allows Reflected XSS. This issue affects Music Store: from n/a through 1.1.19.... Read more
Affected Products :- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
6.4
MEDIUMCVE-2025-24606
Missing Authorization vulnerability in Sprout Invoices Client Invoicing by Sprout Invoices allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Client Invoicing by Sprout Invoices: from n/a through 20.8.1.... Read more
Affected Products : client_invoicing_by_sprout_invoices- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
4.3
MEDIUMCVE-2025-24603
Missing Authorization vulnerability in UkrSolution Print Barcode Labels for your WooCommerce products/orders. This issue affects Print Barcode Labels for your WooCommerce products/orders: from n/a through 3.4.10.... Read more
Affected Products : print_labels_with_barcodes- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
5.3
MEDIUMCVE-2025-24600
Missing Authorization vulnerability in David F. Carr RSVPMarker . This issue affects RSVPMarker : from n/a through 11.4.5.... Read more
Affected Products : rsvpmaker- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
7.1
HIGHCVE-2025-24593
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WisdmLabs Edwiser Bridge allows Reflected XSS. This issue affects Edwiser Bridge: from n/a through 3.0.8.... Read more
- Published: Jan. 27, 2025
- Modified: Feb. 07, 2025
-
5.3
MEDIUMCVE-2025-24590
Missing Authorization vulnerability in Haptiq picu – Online Photo Proofing Gallery allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects picu – Online Photo Proofing Gallery: from n/a through 2.4.0.... Read more
Affected Products :- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
4.3
MEDIUMCVE-2025-24540
Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd allows Cross Site Request Forgery. This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from... Read more
Affected Products :- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025