Latest CVE Feed
-
4.3
CVSS31CVE-2025-47594
Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Soccer Live Scores allows Cross Site Request Forgery. This issue affects Soccer Live Scores: from n/a through 1.0.5.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.9
CVSS31CVE-2025-47593
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonas Hjalmarsson Really Simple Under Construction Page allows Stored XSS. This issue affects Really Simple Under Construction Page: from n/a through 1.4... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.9
CVSS31CVE-2025-47592
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lehel Mátyus Legal Terms and Conditions Popup for User Login and WooCommerce Checkout – TPUL allows Stored XSS. This issue affects Legal Terms and Condit... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47591
Missing Authorization vulnerability in CreedAlly Bulk Featured Image allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Featured Image: from n/a through 1.2.1.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47590
Cross-Site Request Forgery (CSRF) vulnerability in John Dagelmore WPSpeed allows Cross Site Request Forgery. This issue affects WPSpeed: from n/a through 2.6.5.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47589
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook Store allows DOM-Based XSS. This issue affects Ebook Store: from n/a through 5.8007.... Read more
Affected Products : ebook_store- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.6
CVSS31CVE-2025-47587
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows Blind SQL Injection. This issue affects YaySMTP: from n/a through 2.6.4.... Read more
Affected Products : yaysmtp- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47551
Cross-Site Request Forgery (CSRF) vulnerability in ctltwp Wiki Embed allows Cross Site Request Forgery. This issue affects Wiki Embed: from n/a through 1.4.6.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.6
CVSS31CVE-2025-47550
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio allows Upload a Web Shell to a Web Server. This issue affects Instantio: from n/a through 3.3.16.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
9.1
CVSS31CVE-2025-47549
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF allows Upload a Web Shell to a Web Server. This issue affects BEAF: from n/a through 4.6.10.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47548
Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress allows Server Side Request Forgery. This issue affects Wbcom Designs - Activity Link Preview For BuddyPress: from n/a through 1.4.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47547
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter allows Stored XSS. This issue affects SendPulse Email Marketing Newsletter: from n/a through 2.1.6.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.1
CVSS31CVE-2025-47546
Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress allows Cross Site Request Forgery. This issue affects WP Compress: from n/a through 6.30.30.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.3
CVSS31CVE-2025-47545
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Poll Maker allows Leveraging Race Conditions. This issue affects Poll Maker: from n/a through 5.7.7.... Read more
Affected Products : poll_maker- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.6
CVSS31CVE-2025-47544
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce allows Blind SQL Injection. This issue affects Dynamic Pricing With Discount Rules for WooCom... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47543
Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker allows Cross Site Request Forgery. This issue affects TrueBooker: from n/a through 1.0.7.... Read more
Affected Products : truebooker- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47542
Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery. This issue affects Simple calendar for Elementor: from n/a through 1.6.5.... Read more
Affected Products : simple_calendar_for_elementor- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.3
CVSS31CVE-2025-47540
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail allows Retrieve Embedded Sensitive Data. This issue affects weMail: from n/a through 1.14.13.... Read more
Affected Products : wemail- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.6
CVSS31CVE-2025-47538
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart tracking for WooCommerce allows SQL Injection. This issue affects Cart tracking for WooCommerce: from n/a through 1.0.17.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.6
CVSS31CVE-2025-47537
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in add-ons.org PDF Invoices for WooCommerce + Drag and Drop Template Builder allows SQL Injection. This issue affects PDF Invoices for WooCommerce + Drag an... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025