A vulnerability classified as problematic was found in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the file /user/profile of the component Image Handler. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2025-13785. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as problematic has been found in WP Landing Page Plugin up to 0.9.3 on WordPress. Affected by this issue is the function wplp_api_update_text. Performing manipulation results in cross-site request forgery.
This vulnerability is cataloged as CVE-2025-13629. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability described as problematic has been identified in Extra Post Images Plugin up to 1.0 on WordPress. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. Such manipulation of the argument ID leads to cross site scripting.
This vulnerability is listed as CVE-2025-13856. The attack may be performed from remote. There is no available exploit.
A vulnerability marked as problematic has been reported in RevInsite Plugin up to 1.1.0 on WordPress. Affected is an unknown function of the component Shortcode Handler. This manipulation of the argument token causes cross site scripting.
This vulnerability is tracked as CVE-2025-13863. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability labeled as problematic has been found in Cute News Ticker Plugin up to 1.0 on WordPress. This impacts the function Color of the component Shortcode Handler. The manipulation results in cross site scripting.
This vulnerability is identified as CVE-2025-13656. The attack can be executed remotely. There is not any exploit available.
A vulnerability identified as problematic has been detected in Application Passwords Plugin up to 0.1.3 on WordPress. This affects an unknown function. The manipulation of the argument reject_url leads to cross site scripting.
This vulnerability is referenced as CVE-2025-13308. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability categorized as problematic has been discovered in Social Feed Gallery Portfolio Plugin up to 1.3 on WordPress. The impacted element is an unknown function of the component Shortcode Handler. Executing manipulation of the argument ID can lead to cross site scripting.
The identification of this vulnerability is CVE-2025-13896. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in CSS3 Buttons Plugin up to 0.1 on WordPress. It has been rated as problematic. The affected element is an unknown function of the component Shortcode Handler. Performing manipulation results in cross site scripting.
This vulnerability was named CVE-2025-13907. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in List Attachments Shortcode Plugin up to 0.4.1a on WordPress. It has been declared as problematic. Impacted is an unknown function of the component Shortcode Handler. Such manipulation of the argument before_list leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-12717. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Rich Shortcodes for Google Reviews Plugin up to 6.6.2/6.8 on WordPress. It has been classified as problematic. This issue affects some unknown processing of the component Shortcode Handler. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2025-12499. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in TR Timthumb Plugin up to 1.0.4 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Shortcode Handler. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2025-13899. It is possible to launch the attack remotely. No exploit is available.
A vulnerability has been found in Ultra Skype Button Plugin up to 1.0 on WordPress and classified as problematic. This affects the function ultra_skype of the component Shortcode Handler. The manipulation of the argument btn_id leads to cross site scripting.
This vulnerability is traded as CVE-2025-13898. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in Canadian Nutrition Facts Label Plugin up to 3.0 on WordPress. Affected by this issue is some unknown functionality. Executing manipulation of the argument percentage can lead to cross site scripting.
This vulnerability appears as CVE-2025-12715. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as problematic, has been found in Live Sales Notification for Woocommerce Plugin up to 3.6.3 on WordPress. Affected by this vulnerability is an unknown functionality. Performing manipulation of the argument woomotiv_limit results in cross site scripting.
This vulnerability is reported as CVE-2025-13137. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability classified as problematic was found in Booster Plugin up to 2.32.7 on WordPress. Affected is the function get_cache_dir_for_page_from_url. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2025-13377. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as critical has been found in CodeConfig Accessiy Plugin up to 1.0.0 on WordPress. This impacts the function Settings::createPage. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2025-13358. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability described as problematic has been identified in CodeConfig Accessiy Plugin up to 1.0.0 on WordPress. This affects an unknown function of the component Setting Handler. The manipulation results in missing authorization.
This vulnerability is cataloged as CVE-2025-13309. The attack may be launched remotely. There is no exploit available.