Latest CVE Feed
-
6.4
MEDIUMCVE-2025-3488
The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher shortcode in versions 3.6.0 - 4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po... Read more
Affected Products : wpml- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-3438
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of role when registering. This makes it po... Read more
Affected Products : mstore_api- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2025-3858
The Formality plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta... Read more
Affected Products : formality- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-3748
The Taxonomy Chain Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pn_chain_menu shortcode in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping on user supplied attr... Read more
Affected Products : taxonomy_chain_menu- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3709
Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack.... Read more
Affected Products : agentflow- Published: May. 02, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-3708
Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.... Read more
Affected Products : le-yan- Published: May. 02, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-3707
The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to read database contents.... Read more
- Published: May. 02, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-3510
The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p... Read more
- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-1327
The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.4 via the 'homey_delete_user_account' action due to missing validation on a user controlled key. This makes it possible for authentic... Read more
Affected Products : homey- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-1326
The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the homey_reservation_del() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, wit... Read more
Affected Products : homey- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-13420
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various ver... Read more
- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2024-13419
Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for auth... Read more
- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-13418
Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access... Read more
- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-13344
The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'profileId' parameter in all versions up to, and including, 3.3 due to insufficient escaping on the user supplied parameter and lack of suf... Read more
Affected Products : advance_seat_reservation_management_for_woocommerce- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-13322
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up to, and including, 4.88 due to insufficient escaping on the user supplied parameter and lack o... Read more
Affected Products : ads_pro- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-12023
The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.5 to 3.1.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th... Read more
Affected Products : full_-_customer- Published: May. 02, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
7.3
HIGHCVE-2025-4179
The Flynax Bridge plugin for WordPress is vulnerable to limited Privilege Escalation due to a missing capability check on the registerUser() function in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to regi... Read more
Affected Products : flynax_bridge- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-4177
The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteUser() function in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete ar... Read more
Affected Products : flynax_bridge- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-4131
The GmapsMania plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gmap shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i... Read more
Affected Products :- Published: May. 02, 2025
- Modified: May. 02, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3746
The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.14 to 2.0.59. This is due to the plugin not properly validating a user's identity prior to updating their details, like email. Thi... Read more
Affected Products :- Published: May. 02, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication