Hackers are using stolen goods such as credit cards and loyalty points to book travel for sometimes unsuspecting clients, and remote workers, SMBs, travel brands, and others are at risk.
A vulnerability was found in Supreme Addons for Beaver Builder Plugin up to 1.0.9 on WordPress and classified as problematic. Affected by this issue is the function auto_qrcodesabb of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-3669. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in hiWeb Export Posts Plugin up to 0.9.0.0 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the file tool-dashboard-history.php. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-7640. The attack can be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in Harbor up to 2.11.2. Affected is an unknown function. The manipulation of the argument markdown leads to cross site scripting.
This vulnerability is traded as CVE-2025-32019. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in RooCodeInc Roo-Code up to 3.23.18. This issue affects some unknown processing. The manipulation leads to command injection.
The identification of this vulnerability is CVE-2025-54377. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in kyverno JMESPath up to 1.14.1. This vulnerability affects the function non_existent_function of the component JMESPath Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2025-47281. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in OISF libhtp up to 0.5.50. This affects an unknown part of the file suricata.yaml. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2025-53537. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in goauthentik authentik. It has been rated as critical. Affected by this issue is the function request.context["pending_user"].is_active of the component OAuth/SAML. The manipulation leads to improper privilege management.
This vulnerability is handled as CVE-2025-53942. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Affiliate Plus Plugin up to 1.3.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function affiplus_settings of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-7690. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Station Pro Plugin up to 2.4.2 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument width/height leads to cross site scripting.
This vulnerability is traded as CVE-2025-7959. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in iThoughts Advanced Code Editor Plugin up to 1.2.10 on WordPress and classified as problematic. This issue affects the function ithoughts_ace_update_options of the component Setting Handler. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2025-7835. The attack may be initiated remotely. There is no exploit available.
A vulnerability has been found in FunnelCockpit Plugin up to 1.4.2 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation of the argument Error leads to cross site scripting.
This vulnerability was named CVE-2025-6588. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in muse.ai Video Embedding Plugin up to 0.4 on WordPress. This affects the function muse-ai of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-6262. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in WP Get the Table Plugin up to 1.5 on WordPress. Affected by this vulnerability is an unknown functionality of the component Parameter Handler. The manipulation of the argument url leads to cross site scripting.
This vulnerability is known as CVE-2025-6387. The attack can be launched remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in WP Wallcreeper Plugin up to 1.6.1 on WordPress. Affected by this issue is the function admin_notices of the component Cache Handler. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2025-7822. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in WP Applink Plugin up to 0.4.1 on WordPress. Affected is an unknown function. The manipulation of the argument Title leads to cross site scripting.
This vulnerability is traded as CVE-2025-6385. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in Get Youtube Subs Plugin up to 3.5 on WordPress. It has been declared as problematic. This vulnerability affects the function subscribe_link_att. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-7966. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Post Grid Master Plugin up to 3.4.13 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument argsArray['read_more_text'] leads to cross site scripting.
The identification of this vulnerability is CVE-2025-5084. The attack may be initiated remotely. There is no exploit available.