Filtered by vendor Wordpress
Subscriptions
Filtered by product Wordpress
Subscriptions
Total
6029 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-58810 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 5.9 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jimmywb Simple Link List Widget allows Stored XSS. This issue affects Simple Link List Widget: from n/a through 0.3.2. | ||||
CVE-2025-58814 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ram Ratan Maurya Stagtools allows Stored XSS. This issue affects Stagtools: from n/a through 2.3.8. | ||||
CVE-2025-58858 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBean WPB Image Widget allows Stored XSS. This issue affects WPB Image Widget: from n/a through 1.1. | ||||
CVE-2025-58809 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 7.1 High |
Cross-Site Request Forgery (CSRF) vulnerability in Nick Ciske To Lead For Salesforce allows Reflected XSS. This issue affects To Lead For Salesforce: from n/a through 2.7.3.9. | ||||
CVE-2025-58837 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shiful H SS Font Awesome Icon allows Stored XSS. This issue affects SS Font Awesome Icon: from n/a through 4.1.3. | ||||
CVE-2025-58868 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simasicher SimaCookie allows Stored XSS. This issue affects SimaCookie: from n/a through 1.3.2. | ||||
CVE-2025-58815 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 7.2 High |
Deserialization of Untrusted Data vulnerability in Rubel Miah Aitasi Coming Soon allows Object Injection. This issue affects Aitasi Coming Soon: from n/a through 2.0.2. | ||||
CVE-2025-58813 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 4.3 Medium |
Missing Authorization vulnerability in ThemeArile Consultstreet allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Consultstreet: from n/a through 3.0.0. | ||||
CVE-2025-58852 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 7.1 High |
Cross-Site Request Forgery (CSRF) vulnerability in Mark O'Donnell MSTW League Manager allows Stored XSS. This issue affects MSTW League Manager: from n/a through 2.10. | ||||
CVE-2025-58817 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 4.3 Medium |
Missing Authorization vulnerability in DesertThemes SoftMe allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SoftMe: from n/a through 1.1.24. | ||||
CVE-2025-58214 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 8.1 High |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Indutri allows PHP Local File Inclusion. This issue affects Indutri: from n/a through n/a. | ||||
CVE-2025-58783 | 2 Gutentor, Wordpress | 2 Gutentor, Wordpress | 2025-09-07 | 4.3 Medium |
Missing Authorization vulnerability in gutentor Gutentor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gutentor: from n/a through 3.5.1. | ||||
CVE-2025-58793 | 2 Wordpress, Wpbean | 2 Wordpress, Wpb Elementor Addons | 2025-09-07 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBean WPB Elementor Addons allows Stored XSS. This issue affects WPB Elementor Addons: from n/a through 1.6. | ||||
CVE-2025-58821 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 5.9 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdever WP Notification Bell allows Stored XSS. This issue affects WP Notification Bell: from n/a through 1.4.5. | ||||
CVE-2025-53571 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 6.5 Medium |
Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HAPPY: from n/a through 1.0.6. | ||||
CVE-2025-58857 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 7.1 High |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Table of content allows Stored XSS. This issue affects Table of content: from n/a through 1.5.3.1. | ||||
CVE-2025-58792 | 2 Wordpress, Wpkube | 2 Wordpress, Authors List | 2025-09-07 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List allows Cross Site Request Forgery. This issue affects Authors List: from n/a through 2.0.6.1. | ||||
CVE-2025-58865 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in reimund Compact Admin allows Cross Site Request Forgery. This issue affects Compact Admin: from n/a through 1.3.0. | ||||
CVE-2025-58859 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 7.1 High |
Cross-Site Request Forgery (CSRF) vulnerability in David Merinas Add to Feedly allows Stored XSS. This issue affects Add to Feedly: from n/a through 1.2.11. | ||||
CVE-2025-58830 | 1 Wordpress | 1 Wordpress | 2025-09-07 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snagysandor Parallax Scrolling Enllax.js allows Stored XSS. This issue affects Parallax Scrolling Enllax.js: from n/a through 0.0.6. |