Latest CVE Feed
-
7.1
HIGHCVE-2025-53559
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder allows Reflected XSS. This issue affects Universal Video Player - Addon for WPBaker... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.1
HIGHCVE-2025-53319
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Raptive Raptive Ads allows Reflected XSS. This issue affects Raptive Ads: from n/a through 3.8.0.... Read more
Affected Products : raptive_ads- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
9.8
CRITICALCVE-2025-53299
Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer allows Object Injection. This issue affects ThemeMakers Visual Content Composer: from n/a through 1.5.8.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.1
HIGHCVE-2025-53226
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Comments Capcha Box allows Reflected XSS. This issue affects Comments Capcha Box: from n/a through 1.1.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
9.9
CRITICALCVE-2025-53213
Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Conditional Shipping allows Using Malicious Files. This issue affects ReachShip WooCommerce Multi-Carrier & Conditional Shipping: from n/a ... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.1
HIGHCVE-2025-53212
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Revolution Video Player With Bottom Playlist allows Reflected XSS. This issue affects Revolution Video Player With Bottom Playlist: from n/a... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.5
HIGHCVE-2025-53210
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in bdthemes ZoloBlocks allows PHP Local File Inclusion. This issue affects ZoloBlocks: from n/a through 2.3.2.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.5
HIGHCVE-2025-53208
Authorization Bypass Through User-Controlled Key vulnerability in paymayapg Maya Business allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Maya Business: from n/a through 1.2.0.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
8.1
HIGHCVE-2025-53207
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel WP Travel Gutenberg Blocks allows PHP Local File Inclusion. This issue affects WP Travel Gutenberg Blocks: from n/a through ... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.1
HIGHCVE-2025-53205
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Radio Player Shoutcast & Icecast allows Reflected XSS. This issue affects Radio Player Shoutcast & Icecast: from n/a through 4.4.7.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
8.1
HIGHCVE-2025-53204
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme eventlist allows PHP Local File Inclusion. This issue affects eventlist: from n/a through 1.9.2.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.1
HIGHCVE-2025-53201
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster allows Reflected XSS. This issue affects Jobmonster: from n/a through 4.7.8.... Read more
Affected Products : jobmonster- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
8.1
HIGHCVE-2025-53198
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez allows PHP Local File Inclusion. This issue affects Houzez: from n/a through 4.0.4.... Read more
Affected Products : houzez- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
6.5
MEDIUMCVE-2025-53196
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetEngine allows Retrieve Embedded Sensitive Data. This issue affects JetEngine: from n/a through 3.7.0.... Read more
Affected Products : jetengine_for_elementor- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
6.5
MEDIUMCVE-2025-53195
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.0.... Read more
Affected Products : jetengine_for_elementor- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
8.5
HIGHCVE-2025-53194
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Crocoblock JetEngine allows Code Injection. This issue affects JetEngine: from n/a through 3.7.0.... Read more
Affected Products : jetengine_for_elementor- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
4.3
MEDIUMCVE-2025-49896
Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus – Supports Unlimited Channels: from n/a through 1.0.2.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
5.9
MEDIUMCVE-2025-49894
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rewish WP Emmet allows Stored XSS. This issue affects WP Emmet: from n/a through 0.3.4.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
6.5
MEDIUMCVE-2025-49893
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in liseperu Elizaibots allows Stored XSS. This issue affects Elizaibots: from n/a through 1.0.2.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
5.9
MEDIUMCVE-2025-49892
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in badasswp Pending Order Bot allows Stored XSS. This issue affects Pending Order Bot: from n/a through 1.0.2.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025