A vulnerability was found in PDF Catalog for WooCommerce Plugin up to 1.1.18 on WordPress. It has been classified as problematic. This affects an unknown function. Performing manipulation results in cross site scripting.
This vulnerability was named CVE-2025-12191. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as problematic has been discovered in Hide Categories Or Products On Shop Page Plugin up to 1.0.7 on WordPress. Affected by this vulnerability is the function save_data_hcps. The manipulation results in cross-site request forgery.
This vulnerability is identified as CVE-2025-12128. The attack can be executed remotely. There is not any exploit available.
A vulnerability identified as problematic has been detected in Quantic Social Image Hover Plugin up to 1.0.8 on WordPress. Affected by this issue is some unknown functionality of the component Setting Handler. This manipulation causes cross-site request forgery.
This vulnerability is tracked as CVE-2025-13360. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability labeled as problematic has been found in wps Image Optimizer Plugin up to 1.2.0 on WordPress. This affects the function imagopby_ajax_optimize_gallery. Such manipulation leads to cross-site request forgery.
This vulnerability is listed as CVE-2025-12190. The attack may be performed from remote. There is no available exploit.
A vulnerability marked as problematic has been reported in CoSign Single Signon Plugin up to 0.3.1 on WordPress. This vulnerability affects unknown code. Performing manipulation of the argument $_SERVER['PHP_SELF'] results in cross site scripting.
This vulnerability is cataloged as CVE-2025-13512. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability described as problematic has been identified in Omnipress Plugin up to 1.6.3 on WordPress. This issue affects some unknown processing of the component SVG File Handler. Executing manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2025-12163. It is possible to launch the attack remotely. No exploit is available.
A vulnerability classified as problematic was found in Webcake Plugin up to 1.1 on WordPress. The affected element is the function webcake_save_config. The manipulation results in missing authorization.
This vulnerability is reported as CVE-2025-12165. The attack can be launched remotely. No exploit exists.
A vulnerability, which was classified as critical, has been found in Featured Image via URL Plugin up to 0.1 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is listed as CVE-2025-12153. The attack may be initiated remotely. There is no available exploit.
A vulnerability has been found in ContentStudio Plugin up to 1.3.7 on WordPress and classified as critical. This affects the function cstu_update_post. This manipulation causes unrestricted upload.
This vulnerability is registered as CVE-2025-12181. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in Takeads Plugin up to 1.0.13 on WordPress. It has been rated as problematic. The affected element is an unknown function of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-12370. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability labeled as problematic has been found in EPROLO Dropshipping Plugin up to 2.3.1 on WordPress. This impacts the function wp_ajax_eprolo_delete_tracking of the component AJAX Endpoint. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2025-12133. The attack can be launched remotely. No exploit exists.
A vulnerability, which was classified as critical, has been found in Auto Thumbnailer Plugin up to 1.0 on WordPress. This vulnerability affects the function uploadThumb. This manipulation causes unrestricted upload.
This vulnerability is tracked as CVE-2025-12154. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in ContentStudio Plugin up to 1.3.7 on WordPress. It has been declared as problematic. This affects the function add_cstu_settings of the component Setting Handler. The manipulation results in cross-site request forgery.
This vulnerability is reported as CVE-2025-13144. The attack can be launched remotely. No exploit exists.
A vulnerability was found in FitVids Plugin up to 4.0.1 on WordPress. It has been rated as problematic. This impacts an unknown function of the component Setting Handler. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2025-12124. The attack may be initiated remotely. There is no available exploit.
A vulnerability labeled as problematic has been found in Sermon Manager Plugin up to 2.30.0 on WordPress. Affected by this issue is the function sermon-views of the component Shortcode Handler. Executing manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2025-12368. The attack can be executed remotely. There is not any exploit available.
A vulnerability marked as problematic has been reported in Time Sheets Plugin up to 2.1.3 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-10055. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability has been found in SGAI Space1 NAS N1211DS up to 1.0.915 and classified as critical. Impacted is the function RENAME_FILE/OPERATE_FILE/NGNIX_UPLOAD of the file /cgi-bin/JSONAPI of the component gsaiagent. This manipulation causes command injection.
This vulnerability appears as CVE-2025-14184. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.