Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-68037

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atlas Gondal Export Media URLs export-media-urls allows Reflected XSS.This issue affects Export Media URLs: from n/a through <= 2.2.

PUBLISHED
Vendor
Atlas Gondal
Product
Export Media URLs
Provider severity
HIGH
Conflicts
0

CVE-2025-68036

Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CubeWP: from n/a through <= 1.1.27.

PUBLISHED
Vendor
Imran Tauqeer
Product
CubeWP
Provider severity
HIGH
Conflicts
0

CVE-2025-68035

Insertion of Sensitive Information Into Sent Data vulnerability in tabbyai Tabby Checkout tabby-checkout allows Retrieve Embedded Sensitive Data.This issue affects Tabby Checkout: from n/a through <= 5.8.4.

PUBLISHED
Vendor
tabbyai
Product
Tabby Checkout
Provider severity
HIGH
Conflicts
0

CVE-2025-68034

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp allows SQL Injection.This issue affects CleverReach® WP: from n/a through <= 1.5.21.

PUBLISHED
Vendor
CleverReach®
Product
CleverReach® WP
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68033

Insertion of Sensitive Information Into Sent Data vulnerability in Brecht Custom Related Posts custom-related-posts allows Retrieve Embedded Sensitive Data.This issue affects Custom Related Posts: from n/a through <= 1.8.0.

PUBLISHED
Vendor
Brecht
Product
Custom Related Posts
Provider severity
HIGH
Conflicts
0

CVE-2025-68032

Missing Authorization vulnerability in Passionate Brains Advanced WC Analytics advance-wc-analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced WC Analytics: from n/a through <= 3.19.0.

PUBLISHED
Vendor
Passionate Brains
Product
Advanced WC Analytics
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68031

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faraz sms افزونه پیامک حرفه ای فراز اس ام اس farazsms allows Reflected XSS.This issue affects افزونه پیامک حرفه ای فراز اس ام اس: from n/a through <= 2.7.3.

PUBLISHED
Vendor
faraz sms
Product
افزونه پیامک حرفه ای فراز اس ام اس
Provider severity
HIGH
Conflicts
0

CVE-2025-68030

Server-Side Request Forgery (SSRF) vulnerability in WP Messiah Frontis Blocks frontis-blocks allows Server Side Request Forgery.This issue affects Frontis Blocks: from n/a through <= 1.1.5.

PUBLISHED
Vendor
WP Messiah
Product
Frontis Blocks
Provider severity
HIGH
Conflicts
0

CVE-2025-6803

Marvell QConvergeConsole compressDriverFiles Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the compressDriverFiles method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. A

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
HIGH
Conflicts
0

CVE-2025-68029

Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through <= 2.7.3.

PUBLISHED
Vendor
WP Swings
Product
Wallet System for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68028

Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GA4WP: Google Analytics for WordPress: from n/a through <= 2.10.0.

PUBLISHED
Vendor
Passionate Brains
Product
GA4WP: Google Analytics for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68027

Incorrect Privilege Assignment vulnerability in Themefic Hydra Booking hydra-booking allows Privilege Escalation.This issue affects Hydra Booking: from n/a through <= 1.1.32.

PUBLISHED
Vendor
Themefic
Product
Hydra Booking
Provider severity
HIGH
Conflicts
0

CVE-2025-68026

Missing Authorization vulnerability in Niaj Morshed LC Wizard ghl-wizard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LC Wizard: from n/a through <= 2.1.1.

PUBLISHED
Vendor
Niaj Morshed
Product
LC Wizard
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68025

Missing Authorization vulnerability in Addonify Addonify Floating Cart For WooCommerce addonify-floating-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify Floating Cart For WooCommerce: from n/a through <= 1.2.17.

PUBLISHED
Vendor
Addonify
Product
Addonify Floating Cart For WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68024

Missing Authorization vulnerability in Addonify Addonify – WooCommerce Wishlist addonify-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify – WooCommerce Wishlist: from n/a through <= 2.0.15.

PUBLISHED
Vendor
Addonify
Product
Addonify – WooCommerce Wishlist
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68023

Missing Authorization vulnerability in Addonify Addonify – Compare Products For WooCommerce addonify-compare-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify – Compare Products For WooCommerce: from n/a through <= 1.1.17.

PUBLISHED
Vendor
Addonify
Product
Addonify – Compare Products For WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68022

Missing Authorization vulnerability in soporteblue Plugin BlueX for WooCommerce bluex-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Plugin BlueX for WooCommerce: from n/a through <= 3.1.6.

PUBLISHED
Vendor
soporteblue
Product
Plugin BlueX for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2025-68021

Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ConveyThis: from n/a through <= 269.9.

PUBLISHED
Vendor
ConveyThis
Product
ConveyThis
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68020

Missing Authorization vulnerability in WANotifier Notifier notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notifier: from n/a through <= 2.7.13.

PUBLISHED
Vendor
WANotifier
Product
Notifier
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6802

Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the getFileFromURL method. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An atta

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68019

Missing Authorization vulnerability in cleverplugins SEO Booster seo-booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEO Booster: from n/a through <= 6.1.8.

PUBLISHED
Vendor
cleverplugins
Product
SEO Booster
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68018

Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Listener for WooCommerce: from n/a through <= 3.6.1.

PUBLISHED
Vendor
StackWC
Product
Order Listener for WooCommerce
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68017

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Antideo Antideo Email Validator antideo-email-validator allows Blind SQL Injection.This issue affects Antideo Email Validator: from n/a through <= 1.0.10.

PUBLISHED
Vendor
Antideo
Product
Antideo Email Validator
Provider severity
HIGH
Conflicts
0

CVE-2025-68016

Missing Authorization vulnerability in Onepay Sri Lanka onepay Payment Gateway For WooCommerce onepay-payment-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects onepay Payment Gateway For WooCommerce: from n/a through <= 1.1.2.

PUBLISHED
Vendor
Onepay Sri Lanka
Product
onepay Payment Gateway For WooCommerce
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68015

Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.5.

PUBLISHED
Vendor
Vollstart
Product
Event Tickets with Ticket Scanner
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68014

Insertion of Sensitive Information Into Sent Data vulnerability in awethemes AweBooking awebooking allows Retrieve Embedded Sensitive Data.This issue affects AweBooking: from n/a through <= 3.2.26.

PUBLISHED
Vendor
awethemes
Product
AweBooking
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68013

Missing Authorization vulnerability in cardpaysolutions Payment Gateway Authorize.Net CIM for WooCommerce authnet-cim-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway Authorize.Net CIM for WooCommerce: from n/a through <= 2.1.2.

PUBLISHED
Vendor
cardpaysolutions
Product
Payment Gateway Authorize.Net CIM for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68012

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmytro Shteflyuk CodeColorer codecolorer allows Stored XSS.This issue affects CodeColorer: from n/a through <= 0.10.1.

PUBLISHED
Vendor
Dmytro Shteflyuk
Product
CodeColorer
Provider severity
HIGH
Conflicts
0

CVE-2025-68011

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GLS GLS Shipping for WooCommerce gls-shipping-for-woocommerce allows Reflected XSS.This issue affects GLS Shipping for WooCommerce: from n/a through <= 1.4.0.

PUBLISHED
Vendor
GLS
Product
GLS Shipping for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2025-68010

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in netgsm Netgsm netgsm allows Reflected XSS.This issue affects Netgsm: from n/a through <= 2.9.63.

PUBLISHED
Vendor
netgsm
Product
Netgsm
Provider severity
HIGH
Conflicts
0

CVE-2025-6801

Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the saveNICParamsToFile method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
HIGH
Conflicts
0

CVE-2025-68009

Missing Authorization vulnerability in Codeless Slider Templates slider-templates allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Slider Templates: from n/a through <= 1.0.3.

PUBLISHED
Vendor
Codeless
Product
Slider Templates
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68008

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mndpsingh287 WP Mail wp-mail allows Reflected XSS.This issue affects WP Mail: from n/a through <= 1.3.

PUBLISHED
Vendor
mndpsingh287
Product
WP Mail
Provider severity
HIGH
Conflicts
0

CVE-2025-68007

Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf event-espresso-decaf allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Espresso 4 Decaf: from n/a through <= 5.0.37.decaf.

PUBLISHED
Vendor
Event Espresso
Product
Event Espresso 4 Decaf
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68006

Insertion of Sensitive Information Into Sent Data vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Retrieve Embedded Sensitive Data.This issue affects Booking Ultra Pro: from n/a through <= 1.1.23.

PUBLISHED
Vendor
Deetronix
Product
Booking Ultra Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68005

Missing Authorization vulnerability in themewant Easy Hotel Booking easy-hotel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Hotel Booking: from n/a through <= 1.9.2.

PUBLISHED
Vendor
themewant
Product
Easy Hotel Booking
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68004

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kapil Chugh My Post Order my-posts-order allows Reflected XSS.This issue affects My Post Order: from n/a through <= 1.2.1.1.

PUBLISHED
Vendor
Kapil Chugh
Product
My Post Order
Provider severity
HIGH
Conflicts
0

CVE-2025-68003

Missing Authorization vulnerability in renatoatshown Shown Connector shown-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shown Connector: from n/a through <= 1.2.10.

PUBLISHED
Vendor
renatoatshown
Product
Shown Connector
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68002

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 100plugins Open User Map open-user-map allows Path Traversal.This issue affects Open User Map: from n/a through <= 1.4.16.

PUBLISHED
Vendor
100plugins
Product
Open User Map
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68001

Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a Web Shell to a Web Server.This issue affects g-FFL Checkout: from n/a through <= 2.1.0.

PUBLISHED
Vendor
garidium
Product
g-FFL Checkout
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68000

Missing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonial Slider: from n/a through <= 2.0.15.

PUBLISHED
Vendor
PickPlugins
Product
Testimonial Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6800

Marvell QConvergeConsole restoreESwitchConfig Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the restoreESwitchConfig method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations.

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
HIGH
Conflicts
0

CVE-2025-67999

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stefano Lissa Newsletter newsletter allows Blind SQL Injection.This issue affects Newsletter: from n/a through <= 9.0.9.

PUBLISHED
Vendor
Stefano Lissa
Product
Newsletter
Provider severity
HIGH
Conflicts
0

CVE-2025-67998

Authentication Bypass Using an Alternate Path or Channel vulnerability in kamleshyadav Miraculous Elementor miraculous-el allows Authentication Abuse.This issue affects Miraculous Elementor: from n/a through <= 2.0.7.

PUBLISHED
Vendor
kamleshyadav
Product
Miraculous Elementor
Provider severity
HIGH
Conflicts
0

CVE-2025-67997

Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This issue affects Travelicious: from n/a through < 1.6.7.

PUBLISHED
Vendor
BoldThemes
Product
Travelicious
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67996

Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects Nestin: from n/a through < 1.2.6.

PUBLISHED
Vendor
BoldThemes
Product
Nestin
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67995

Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affects PatioTime: from n/a through < 2.1.

PUBLISHED
Vendor
LoftOcean
Product
PatioTime
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67994

Missing Authorization vulnerability in YayCommerce YayCurrency yaycurrency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayCurrency: from n/a through <= 3.3.

PUBLISHED
Vendor
YayCommerce
Product
YayCurrency
Provider severity
HIGH
Conflicts
0

CVE-2025-67993

Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.2.1.

PUBLISHED
Vendor
Vito Peleg
Product
Atarim
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67992

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean PatioTime patiotime allows PHP Local File Inclusion.This issue affects PatioTime: from n/a through < 2.1.

PUBLISHED
Vendor
LoftOcean
Product
PatioTime
Provider severity
HIGH
Conflicts
0