Aggregator
CVE-2025-32622 | OTP-less One Tap Sign in Plugin up to 2.0.58 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability was found in OTP-less One Tap Sign in Plugin up to 2.0.58 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-32622. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-32613 | Bowo Debug Log Manager Plugin up to 2.3.4 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability was found in Bowo Debug Log Manager Plugin up to 2.3.4 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-32613. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-32605 | expresstechsoftware MemberPress Discord Addon Plugin up to 1.1.1 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability was found in expresstechsoftware MemberPress Discord Addon Plugin up to 1.1.1 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-32605. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-32602 | aiiddqd WooMS Plugin up to 9.12 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability has been found in aiiddqd WooMS Plugin up to 9.12 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-32602. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-32609 | Picture-Planet Verowa Connect Plugin up to 3.0.4 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability was found in Picture-Planet Verowa Connect Plugin up to 3.0.4 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-32609. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-32636 | matthewrubin Local Magic Plugin up to 2.6.0 on WordPress sql injection
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in matthewrubin Local Magic Plugin up to 2.6.0 on WordPress. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-32636. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-32608 | Movylo Marketing Automation Plugin up to 2.0.7 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Movylo Marketing Automation Plugin up to 2.0.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-32608. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-39586 | Metagauss ProfileGrid Plugin up to 5.9.4.8 on WordPress sql injection
9 months 3 weeks ago
A vulnerability classified as critical was found in Metagauss ProfileGrid Plugin up to 5.9.4.8 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2025-39586. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-39595 | Quentn WP Plugin up to 1.2.8 on WordPress sql injection
9 months 3 weeks ago
A vulnerability classified as critical has been found in Quentn WP Plugin up to 1.2.8 on WordPress. Affected is an unknown function. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2025-39595. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-39588 | bdthemes Ultimate Store Kit Elementor Addons Plugin up to 2.4.0 on WordPress deserialization
9 months 3 weeks ago
A vulnerability was found in bdthemes Ultimate Store Kit Elementor Addons Plugin up to 2.4.0 on WordPress. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to deserialization.
This vulnerability was named CVE-2025-39588. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-39587 | Stylemix Cost Calculator Builder Plugin up to 3.2.65 on WordPress sql injection
9 months 3 weeks ago
A vulnerability was found in Stylemix Cost Calculator Builder Plugin up to 3.2.65 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2025-39587. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-39583 | BERTHA AI Plugin up to 1.12.10.2 on WordPress authorization
9 months 3 weeks ago
A vulnerability was found in BERTHA AI Plugin up to 1.12.10.2 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2025-39583. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-39569 | Taskbuilder Plugin up to 4.0.1 on WordPress sql injection
9 months 3 weeks ago
A vulnerability was found in Taskbuilder Plugin up to 4.0.1 on WordPress and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2025-39569. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-32626 | JoomSky JS Job Manager Plugin up to 2.0.2 on WordPress sql injection
9 months 3 weeks ago
A vulnerability has been found in JoomSky JS Job Manager Plugin up to 2.0.2 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2025-32626. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-39526 | nicdark Hotel Booking Plugin up to 3.6 on WordPress filename control
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in nicdark Hotel Booking Plugin up to 3.6 on WordPress. This issue affects some unknown processing. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2025-39526. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-39559 | Eivin Landa Bring Fraktguiden for WooCommerce Plugin up to 1.11.4 on WordPress authorization
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Eivin Landa Bring Fraktguiden for WooCommerce Plugin up to 1.11.4 on WordPress. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-39559. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-32660 | JoomSky JS Job Manager Plugin up to 2.0.2 on WordPress unrestricted upload
9 months 3 weeks ago
A vulnerability classified as critical was found in JoomSky JS Job Manager Plugin up to 2.0.2 on WordPress. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2025-32660. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-32635 | Hive Support Plugin up to 1.2.2 on WordPress insertion of sensitive information into sent data
9 months 3 weeks ago
A vulnerability classified as problematic has been found in Hive Support Plugin up to 1.2.2 on WordPress. This affects an unknown part. The manipulation leads to insertion of sensitive information into sent data.
This vulnerability is uniquely identified as CVE-2025-32635. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-32682 | RomanCode MapSVG Lite Plugin up to 8.5.34 on WordPress unrestricted upload
9 months 3 weeks ago
A vulnerability was found in RomanCode MapSVG Lite Plugin up to 8.5.34 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2025-32682. The attack may be launched remotely. There is no exploit available.
vuldb.com