Latest CVE Feed
-
8.1
HIGHCVE-2025-49036
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addons for KingComposer allows PHP Local File Inclusion. This issue affects Premium Addons for KingComposer: ... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
8.5
HIGHCVE-2025-49033
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows Blind SQL Injection. This issue affects ProfileGrid : from n/a through 5.9.5.3.... Read more
Affected Products : profilegrid- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2025-48332
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks allows PHP Local File Inclusion. This issue affects Gutenberg Blocks: from n/a through 3.3.1.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2025-48293
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dylan Kuhn Geo Mashup allows PHP Local File Inclusion. This issue affects Geo Mashup: from n/a through 1.13.16.... Read more
Affected Products : geo_mashup- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-47689
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in johnh10 Video Blogster Lite allows Reflected XSS. This issue affects Video Blogster Lite: from n/a through 1.2.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-47610
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wetail WooCommerce Fortnox Integration allows Stored XSS. This issue affects WooCommerce Fortnox Integration: from n/a through 4.5.6.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.2
HIGHCVE-2025-47536
Deserialization of Untrusted Data vulnerability in keywordrush Content Egg allows Object Injection. This issue affects Content Egg: from n/a through 7.0.0.... Read more
Affected Products : content_egg- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2025-3703
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wipeoutmedia CSS & JavaScript Toolbox allows PHP Local File Inclusion. This issue affects CSS & JavaScript Toolbox: from n/a through n... Read more
Affected Products : css_\&_javascript_toolbox- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
8.5
HIGHCVE-2025-39510
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Pinterest Automatic Pin allows SQL Injection. This issue affects Pinterest Automatic Pin: from n/a through n/a.... Read more
Affected Products : pinterest_automatic_pin- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-39483
Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer allows Code Injection. This issue affects Eventer: from n/a through 3.9.6.... Read more
Affected Products : eventer- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2025-32288
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions allows PHP Local File Inclusion. This issue affects RT-Theme 18 | Extensions: from n/a through 2.4.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2025-31425
Missing Authorization vulnerability in kamleshyadav WP Lead Capturing Pages allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Lead Capturing Pages: from n/a through 2.3.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-31007
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alvind Billplz Addon for Contact Form 7 allows Reflected XSS. This issue affects Billplz Addon for Contact Form 7: from n/a through 1.2.0.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
8.5
HIGHCVE-2025-30998
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rico Macchi WP Links Page allows SQL Injection. This issue affects WP Links Page: from n/a through 4.9.6.... Read more
Affected Products : wp_links_page- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-30993
Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Thank You Page Customizer for WooCommerce – Incre... Read more
Affected Products : woocommerce_thank_you_page_customizer- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2025-30639
Missing Authorization vulnerability in ThemeAtelier IDonatePro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects IDonatePro: from n/a through 2.1.9.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
8.1
HIGHCVE-2025-30635
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeAtelier IDonatePro allows PHP Local File Inclusion. This issue affects IDonatePro: from n/a through 2.1.9.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-30626
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon for WPBakery Page Builder allows Reflected XSS. This issue affects Multimedia Playlist Slider Addon for WPB... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-29014
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt FoodMenu allows Reflected XSS. This issue affects FoodMenu: from n/a through 1.20.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-28999
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt WooCommerce Shop Page Builder allows Reflected XSS. This issue affects WooCommerce Shop Page Builder: from n/a through 2.27.7.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025