Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-67580

Missing Authorization vulnerability in Constant Contact Constant Contact + WooCommerce constant-contact-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant Contact + WooCommerce: from n/a through <= 2.4.1.

PUBLISHED
Vendor
Constant Contact
Product
Constant Contact + WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6758

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to arbitrarily choose their role, including the Administrator role, during user registration.

PUBLISHED
Vendor
imithemes
Product
Real Spaces - WordPress Properties Directory Theme
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67579

Missing Authorization vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Extra Fields: from n/a through <= 16.8.

PUBLISHED
Vendor
vanquish
Product
User Extra Fields
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67578

Missing Authorization vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Email Capture: from n/a through <= 3.12.4.

PUBLISHED
Vendor
Rhys Wynne
Product
WP Email Capture
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67577

Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.8.20.

PUBLISHED
Vendor
hassantafreshi
Product
Easy Form Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67576

Missing Authorization vulnerability in QuantumCloud Simple Link Directory simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through <= 8.8.3.

PUBLISHED
Vendor
QuantumCloud
Product
Simple Link Directory
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67575

Missing Authorization vulnerability in Andrew Lima Sitewide Notice WP sitewide-notice-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sitewide Notice WP: from n/a through <= 2.4.1.

PUBLISHED
Vendor
Andrew Lima
Product
Sitewide Notice WP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67574

Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.30.

PUBLISHED
Vendor
wpdevart
Product
Booking calendar, Appointment Booking System
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67573

Missing Authorization vulnerability in ThimPress Sailing sailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sailing: from n/a through < 4.4.6.

PUBLISHED
Vendor
ThimPress
Product
Sailing
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67572

Missing Authorization vulnerability in PenciDesign PenNews pennews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PenNews: from n/a through < 6.7.4.

PUBLISHED
Vendor
PenciDesign
Product
PenNews
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67571

Missing Authorization vulnerability in WPFunnels WPFunnels wpfunnels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPFunnels: from n/a through <= 3.6.2.

PUBLISHED
Vendor
WPFunnels
Product
WPFunnels
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67570

Missing Authorization vulnerability in WesternDeal WPForms Google Sheet Connector gsheetconnector-wpforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPForms Google Sheet Connector: from n/a through <= 4.0.0.

PUBLISHED
Vendor
WesternDeal
Product
WPForms Google Sheet Connector
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6757

The Recent Posts Widget Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rpwe' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
themejunkie
Product
Recent Posts Widget Extended
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67569

Missing Authorization vulnerability in scriptsbundle AdForest adforest allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AdForest: from n/a through <= 6.0.11.

PUBLISHED
Vendor
scriptsbundle
Product
AdForest
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67568

Missing Authorization vulnerability in xtemos Basel basel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Basel: from n/a through <= 5.9.1.

PUBLISHED
Vendor
xtemos
Product
Basel
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67567

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in uixthemes Sober sober allows Retrieve Embedded Sensitive Data.This issue affects Sober: from n/a through <= 3.5.11.

PUBLISHED
Vendor
uixthemes
Product
Sober
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67566

Missing Authorization vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woffice Core: from n/a through <= 5.4.30.

PUBLISHED
Vendor
WofficeIO
Product
Woffice Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67565

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in sizam Rehub rehub-theme allows Retrieve Embedded Sensitive Data.This issue affects Rehub: from n/a through <= 19.9.9.1.

PUBLISHED
Vendor
sizam
Product
Rehub
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67564

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in alekv Pixel Manager for WooCommerce woocommerce-google-adwords-conversion-tracking-tag allows Retrieve Embedded Sensitive Data.This issue affects Pixel Manager for WooCommerce: from n/a through <= 1.51.1.

PUBLISHED
Vendor
alekv
Product
Pixel Manager for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67563

Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 3.6.1.

PUBLISHED
Vendor
Saad Iqbal
Product
Post SMTP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67562

Missing Authorization vulnerability in WebCodingPlace Image Caption Hover Pro image-caption-hover-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Caption Hover Pro: from n/a through < 20.0.

PUBLISHED
Vendor
WebCodingPlace
Product
Image Caption Hover Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67561

Missing Authorization vulnerability in Oleksandr Lysyi Debug Log Viewer debug-log-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Debug Log Viewer: from n/a through <= 2.0.3.

PUBLISHED
Vendor
Oleksandr Lysyi
Product
Debug Log Viewer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67560

Missing Authorization vulnerability in Webilia Inc. Listdom listdom allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Listdom: from n/a through <= 5.0.1.

PUBLISHED
Vendor
Webilia Inc.
Product
Listdom
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6756

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's UACF7_CUSTOM_FIELDS shortcode in all versions up to, and including, 3.5.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
themefic
Product
Ultra Addons for Contact Form 7
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67559

Missing Authorization vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5.

PUBLISHED
Vendor
vcita
Product
Online Booking & Scheduling Calendar for WordPress by vcita
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67558

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacques Malgrange Rencontre rencontre allows Stored XSS.This issue affects Rencontre: from n/a through <= 3.13.7.

PUBLISHED
Vendor
Jacques Malgrange
Product
Rencontre
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67557

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Stored XSS.This issue affects WP eBay Product Feeds: from n/a through <= 3.4.9.

PUBLISHED
Vendor
Rhys Wynne
Product
WP eBay Product Feeds
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67556

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHigh Advanced FAQ Manager advanced-faq-manager allows Stored XSS.This issue affects Advanced FAQ Manager: from n/a through <= 1.5.2.

PUBLISHED
Vendor
ThemeHigh
Product
Advanced FAQ Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67555

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in useStrict UseStrict's Calendly Embedder cal-embedder-lite allows Stored XSS.This issue affects UseStrict's Calendly Embedder: from n/a through <= 1.1.7.2.

PUBLISHED
Vendor
useStrict
Product
UseStrict's Calendly Embedder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67554

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Humanityco Cookie Notice & Compliance for GDPR / CCPA cookie-notice allows Stored XSS.This issue affects Cookie Notice & Compliance for GDPR / CCPA: from n/a through <= 2.5.8.

PUBLISHED
Vendor
Humanityco
Product
Cookie Notice & Compliance for GDPR / CCPA
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67553

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHigh Advanced FAQ Manager advanced-faq-manager allows DOM-Based XSS.This issue affects Advanced FAQ Manager: from n/a through <= 1.5.2.

PUBLISHED
Vendor
ThemeHigh
Product
Advanced FAQ Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67552

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WalkerWP Walker Core walker-core allows DOM-Based XSS.This issue affects Walker Core: from n/a through <= 1.3.17.

PUBLISHED
Vendor
WalkerWP
Product
Walker Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67551

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wappointment team Wappointment wappointment allows Stored XSS.This issue affects Wappointment: from n/a through <= 2.6.9.

PUBLISHED
Vendor
Wappointment team
Product
Wappointment
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67550

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rhewlif Donation Thermometer donation-thermometer allows Stored XSS.This issue affects Donation Thermometer: from n/a through <= 2.2.6.

PUBLISHED
Vendor
rhewlif
Product
Donation Thermometer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6755

The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajaxDeleteTheme() function in all versions up to, and including, 1.3.0. This makes it possible for Subscriber-level attackers to add arbitrary file paths (such as ../../../../wp-config.php) to the themeNameId parameter of the AJAX request, which can lead to remote code execution.

PUBLISHED
Vendor
gameusers
Product
Game Users Share Buttons
Provider severity
HIGH
Conflicts
0

CVE-2025-67549

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oik allows DOM-Based XSS.This issue affects oik: from n/a through <= 4.15.3.

PUBLISHED
Vendor
bobbingwide
Product
oik
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67548

Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.1.

PUBLISHED
Vendor
WP Delicious
Product
WP Delicious
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67547

Missing Authorization vulnerability in uixthemes Konte konte allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Konte: from n/a through <= 2.4.6.

PUBLISHED
Vendor
uixthemes
Product
Konte
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67546

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Retrieve Embedded Sensitive Data.This issue affects WP ERP: from n/a through <= 1.16.6.

PUBLISHED
Vendor
weDevs
Product
WP ERP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67545

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FirePlugins FireBox firebox allows Stored XSS.This issue affects FireBox: from n/a through <= 3.1.0-free.

PUBLISHED
Vendor
FirePlugins
Product
FireBox
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67544

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Shopkeeper Extender shopkeeper-extender allows Stored XSS.This issue affects Shopkeeper Extender: from n/a through < 7.0.

PUBLISHED
Vendor
Get Bowtied
Product
Shopkeeper Extender
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67543

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Catch Themes Essential Widgets essential-widgets allows Stored XSS.This issue affects Essential Widgets: from n/a through <= 2.2.2.

PUBLISHED
Vendor
Catch Themes
Product
Essential Widgets
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67542

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SilkyPress Multi-Step Checkout for WooCommerce wp-multi-step-checkout allows DOM-Based XSS.This issue affects Multi-Step Checkout for WooCommerce: from n/a through <= 2.33.

PUBLISHED
Vendor
SilkyPress
Product
Multi-Step Checkout for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67541

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lester Chan WP-ShowHide wp-showhide allows Stored XSS.This issue affects WP-ShowHide: from n/a through <= 1.05.

PUBLISHED
Vendor
Lester Chan
Product
WP-ShowHide
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67540

Missing Authorization vulnerability in Wealcoder Animation Addons for Elementor animation-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animation Addons for Elementor: from n/a through <= 2.4.5.

PUBLISHED
Vendor
Wealcoder
Product
Animation Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6754

The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function in all versions up to, and including, 1.0.15. Because the AJAX action only verifies a nonce, without checking the caller’s capabilities, a subscriber-level user can retrieve the token and then access the custom endpoint to obtain full administrator cookies.

PUBLISHED
Vendor
seometricsplugin
Product
SEO Metrics
Provider severity
HIGH
Conflicts
0

CVE-2025-67539

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Select Core select-core allows DOM-Based XSS.This issue affects Select Core: from n/a through < 2.6.

PUBLISHED
Vendor
Select-Themes
Product
Select Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67538

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews Gallery jnews-gallery allows Stored XSS.This issue affects JNews Gallery: from n/a through < 12.0.1.

PUBLISHED
Vendor
jegtheme
Product
JNews Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67537

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blair Williams ThirstyAffiliates thirstyaffiliates allows Stored XSS.This issue affects ThirstyAffiliates: from n/a through <= 3.11.8.

PUBLISHED
Vendor
Blair Williams
Product
ThirstyAffiliates
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67536

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress learnpress allows Stored XSS.This issue affects LearnPress: from n/a through <= 4.2.9.4.

PUBLISHED
Vendor
ThimPress
Product
LearnPress
Provider severity
MEDIUM
Conflicts
0