Latest CVE Feed
-
7.5
HIGHCVE-2025-49870
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions allows SQL Injection. This issue affects Paid Member Subscriptions: from n/a through 2.15.1.... Read more
Affected Products : paid_membership_subscriptions- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2025-49867
Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes allows Privilege Escalation. This issue affects RealHomes: from n/a through 4.4.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-49866
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikel Beautiful Cookie Consent Banner allows Reflected XSS. This issue affects Beautiful Cookie Consent Banner: from n/a through 4.6.1.... Read more
Affected Products : beautiful_cookie_consent_banner- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.5
MEDIUMCVE-2025-49431
Missing Authorization vulnerability in Gnuget MF Plus WPML allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MF Plus WPML: from n/a through 1.1.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.2
HIGHCVE-2025-49418
Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allows Server Side Request Forgery. This issue affects Allmart: from n/a through 1.0.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2025-49417
Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action allows Object Injection. This issue affects WooCommerce Product Multi-Action: from n/a through 1.3.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
10.0
CRITICALCVE-2025-49414
Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery allows Using Malicious Files. This issue affects FW Gallery: from n/a through 8.0.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.8
MEDIUMCVE-2025-49303
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps allows Path Traversal. This issue affects Frontend Admin by DynamiApps: from n/a through 3.28.7.... Read more
Affected Products : frontend_admin- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
10.0
CRITICALCVE-2025-49302
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe allows Remote Code Inclusion. This issue affects Easy Stripe: from n/a through 1.1.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-49274
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awplife Neom Blog allows Reflected XSS. This issue affects Neom Blog: from n/a through 0.0.9.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-49247
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Team Showcase allows DOM-Based XSS. This issue affects Team Showcase: from n/a through n/a.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-49245
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Testimonials Showcase allows Reflected XSS. This issue affects Testimonials Showcase: from n/a through 1.9.16.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.5
HIGHCVE-2025-49070
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Elessi allows PHP Local File Inclusion. This issue affects Elessi: from n/a through n/a.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.5
MEDIUMCVE-2025-48231
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form allows Stored XSS. This issue affects Booking Calendar Contact Form: from n/a through 1.2.58.... Read more
Affected Products : booking_calendar- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.5
MEDIUMCVE-2025-47634
Missing Authorization vulnerability in Keylor Mendoza WC Pickup Store allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WC Pickup Store: from n/a through 1.8.9.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.5
HIGHCVE-2025-47627
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LCweb PrivateContent - Mail Actions allows PHP Local File Inclusion. This issue affects PrivateContent - Mail Actions: from n/a throug... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.3
MEDIUMCVE-2025-47565
Missing Authorization vulnerability in ashanjay EventON allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventON: from n/a through 4.9.9.... Read more
Affected Products : eventon-lite- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2025-47479
Weak Authentication vulnerability in AresIT WP Compress allows Authentication Abuse. This issue affects WP Compress: from n/a through 6.30.30.... Read more
Affected Products : wp_compress- Published: Jul. 04, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-39487
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Rankie allows Reflected XSS. This issue affects Rankie: from n/a through 1.8.2.... Read more
Affected Products : rankie- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-32311
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Pressroom - News Magazine WordPress Theme allows Reflected XSS. This issue affects Pressroom - News Magazine WordPress Theme: from n/a throu... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025