Latest CVE Feed
-
4.4
MEDIUMCVE-2025-24701
Server-Side Request Forgery (SSRF) vulnerability in Kiboko Labs Chained Quiz allows Server Side Request Forgery. This issue affects Chained Quiz: from n/a through 1.3.2.9.... Read more
Affected Products : chained_quiz- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2025-24698
Cross-Site Request Forgery (CSRF) vulnerability in G5Theme Essential Real Estate allows Cross Site Request Forgery. This issue affects Essential Real Estate: from n/a through 5.1.8.... Read more
Affected Products : essential_real_estate- Published: Jan. 24, 2025
- Modified: Jun. 09, 2025
-
4.3
MEDIUMCVE-2025-24696
Cross-Site Request Forgery (CSRF) vulnerability in WP Attire Attire Blocks allows Cross Site Request Forgery. This issue affects Attire Blocks: from n/a through 1.9.6.... Read more
Affected Products : attire_blocks- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
4.4
MEDIUMCVE-2025-24695
Server-Side Request Forgery (SSRF) vulnerability in HasThemes Extensions For CF7 allows Server Side Request Forgery. This issue affects Extensions For CF7: from n/a through 3.2.0.... Read more
Affected Products : extensions_for_cf7- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2025-24693
Missing Authorization vulnerability in Yehi Advanced Notifications allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced Notifications: from n/a through 1.2.7.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2025-24691
Missing Authorization vulnerability in Gagan Sandhu , Enej Bajgoric , CTLT DEV, UBC People Lists allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects People Lists: from n/a through 1.3.10.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
6.5
MEDIUMCVE-2025-24687
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lars Wallenborn Show/Hide Shortcode allows Stored XSS. This issue affects Show/Hide Shortcode: from n/a through 1.0.0.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
7.6
HIGHCVE-2025-24683
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill RSVP and Event Management Plugin allows SQL Injection. This issue affects RSVP and Event Management Plugin: from n/a through 2.7.14.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2025-24682
Missing Authorization vulnerability in mikemmx Super Block Slider allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Super Block Slider: from n/a through 2.7.9.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
5.9
MEDIUMCVE-2025-24681
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce allows Stored XSS. This issue affects Product Carousel Slider & Grid Ultimate for WooCommer... Read more
Affected Products : product_carousel_slider_\&_grid_ultimate_for_woocommerce- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2025-24679
Missing Authorization vulnerability in webraketen Internal Links Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Internal Links Manager: from n/a through 2.5.2.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
6.5
MEDIUMCVE-2025-24678
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Listamester Listamester allows Stored XSS. This issue affects Listamester: from n/a through 2.3.4.... Read more
Affected Products : listamester- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
6.5
MEDIUMCVE-2025-24675
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.2.... Read more
Affected Products : wp_visitor_statistics- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
5.9
MEDIUMCVE-2025-24674
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Teplitsa. Technologies for Social Good ShMapper by Teplitsa allows Stored XSS. This issue affects ShMapper by Teplitsa: from n/a through 1.5.0.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
6.5
MEDIUMCVE-2025-24673
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AyeCode Ltd Ketchup Shortcodes allows Stored XSS. This issue affects Ketchup Shortcodes: from n/a through 0.1.2.... Read more
Affected Products : ketchup_shortcodes- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
8.5
HIGHCVE-2025-24672
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodePeople Form Builder CP allows SQL Injection. This issue affects Form Builder CP: from n/a through 1.2.41.... Read more
Affected Products : form_builder_cp- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
8.5
HIGHCVE-2025-24669
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SERPed SERPed.net allows SQL Injection. This issue affects SERPed.net: from n/a through 4.4.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
5.9
MEDIUMCVE-2025-24668
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle PPOM for WooCommerce allows Stored XSS. This issue affects PPOM for WooCommerce: from n/a through 33.0.8.... Read more
Affected Products : product_addons_\&_fields_for_woocommerce- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
5.9
MEDIUMCVE-2025-24666
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeIsle AI Chatbot for WordPress – Hyve Lite allows Stored XSS. This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through 1.2.2.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
7.6
HIGHCVE-2025-24663
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Ruhul Amin, Josh Lobe Simple Download Monitor allows Blind SQL Injection. This issue affects Simple Download Monitor: from n/a throug... Read more
Affected Products : simple_download_monitor- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025