Aggregator
Interlock
1 year 1 month ago
cohenido
CVE-2025-3867 | Ajax Comment Form CST Plugin up to 1.2 on WordPress cross-site request forgery
1 year 1 month ago
A vulnerability, which was classified as problematic, was found in Ajax Comment Form CST Plugin up to 1.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-3867. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-3866 | Add Google +1 Social Share Button Plugin up to 1.0.0 on WordPress cross-site request forgery
1 year 1 month ago
A vulnerability, which was classified as problematic, has been found in Add Google +1 Social Share Button Plugin up to 1.0.0 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-3866. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-3861 | Prevent Direct Access Plugin up to 2.8.8.2 on WordPress pda_lite_custom_permission_check improper authorization
1 year 1 month ago
A vulnerability classified as critical was found in Prevent Direct Access Plugin up to 2.8.8.2 on WordPress. Affected by this vulnerability is the function pda_lite_custom_permission_check. The manipulation leads to improper authorization.
This vulnerability is known as CVE-2025-3861. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2580 | Bit Contact Form Form Plugin up to 2.18.3 on WordPress SVG File Upload cross site scripting
1 year 1 month ago
A vulnerability classified as problematic has been found in Bit Contact Form Form Plugin up to 2.18.3 on WordPress. Affected is an unknown function of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-2580. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-3752 | Able Player, Accessible HTML5 Media Player Plugin up to 1.2.1 on WordPress preload cross site scripting
1 year 1 month ago
A vulnerability was found in Able Player, Accessible HTML5 Media Player Plugin up to 1.2.1 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument preload leads to cross site scripting.
This vulnerability was named CVE-2025-3752. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-3868 | Custom Admin-Bar Favorites Plugin up to 0.1 on WordPress menuObject cross site scripting
1 year 1 month ago
A vulnerability was found in Custom Admin-Bar Favorites Plugin up to 0.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument menuObject leads to cross site scripting.
The identification of this vulnerability is CVE-2025-3868. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-3775 | ShopLentor Plugin up to 3.1.2 on WordPress woolentor_template_proxy server-side request forgery
1 year 1 month ago
A vulnerability was found in ShopLentor Plugin up to 3.1.2 on WordPress. It has been classified as critical. This affects the function woolentor_template_proxy. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2025-3775. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-3743 | Upsell Funnel Builder for WooCommerce Plugin up to 3.0.0 on WordPress add_offer_in_cart ID/discount external control of assumed-immutable web parameter
1 year 1 month ago
A vulnerability was found in Upsell Funnel Builder for WooCommerce Plugin up to 3.0.0 on WordPress and classified as critical. Affected by this issue is the function add_offer_in_cart. The manipulation of the argument ID/discount leads to external control of assumed-immutable web parameter.
This vulnerability is handled as CVE-2025-3743. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-3923 | Prevent Direct Access Plugin up to 2.8.8 on WordPress information disclosure
1 year 1 month ago
A vulnerability has been found in Prevent Direct Access Plugin up to 2.8.8 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2025-3923. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2238 | Vikinger Theme up to 1.9.30 on WordPress vikinger_user_meta_update_ajax privileges management
1 year 1 month ago
A vulnerability, which was classified as critical, was found in Vikinger Theme up to 1.9.30 on WordPress. Affected is the function vikinger_user_meta_update_ajax. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2025-2238. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-46528 | Steve Availability Calendar Plugin up to 0.2.4 on WordPress cross-site request forgery
1 year 1 month ago
A vulnerability, which was classified as problematic, has been found in Steve Availability Calendar Plugin up to 0.2.4 on WordPress. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2025-46528. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-46534 | DanielRiera Image Style Hover Plugin up to 1.0.6 on WordPress cross site scripting
1 year 1 month ago
A vulnerability classified as problematic was found in DanielRiera Image Style Hover Plugin up to 1.0.6 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-46534. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-46540 | Chris Mok GNA Search Shortcode Plugin up to 0.9.5 on WordPress cross site scripting
1 year 1 month ago
A vulnerability was found in Chris Mok GNA Search Shortcode Plugin up to 0.9.5 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-46540. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-46530 | HuangYe WuDeng Hacklog Remote Attachment Plugin up to 1.3.2 on WordPress cross-site request forgery
1 year 1 month ago
A vulnerability classified as problematic has been found in HuangYe WuDeng Hacklog Remote Attachment Plugin up to 1.3.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-46530. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-46541 | elrata WP-reCAPTCHA-bp Plugin up to 4.1 on WordPress cross site scripting
1 year 1 month ago
A vulnerability was found in elrata WP-reCAPTCHA-bp Plugin up to 4.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-46541. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-46532 | Haris Zulfiqar Tooltip Plugin up to 1.0.1 on WordPress cross site scripting
1 year 1 month ago
A vulnerability was found in Haris Zulfiqar Tooltip Plugin up to 1.0.1 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-46532. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-46538 | webplanetsoft Inline Text Popup Plugin up to 1.0.0 on WordPress cross site scripting
1 year 1 month ago
A vulnerability was found in webplanetsoft Inline Text Popup Plugin up to 1.0.0 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-46538. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-46529 | StressFree Sites Business Contact Widget Plugin up to 2.7.0 on WordPress cross site scripting
1 year 1 month ago
A vulnerability, which was classified as problematic, was found in StressFree Sites Business Contact Widget Plugin up to 2.7.0 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-46529. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com