Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-64277

Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.9.

PUBLISHED
Vendor
QuantumCloud
Product
ChatBot
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64276

Missing Authorization vulnerability in Ays Pro Survey Maker survey-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through <= 5.1.9.4.

PUBLISHED
Vendor
Ays Pro
Product
Survey Maker
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64275

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Manager booking-manager allows Stored XSS.This issue affects Booking Manager: from n/a through <= 2.1.17.

PUBLISHED
Vendor
wpdevelop
Product
Booking Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64274

Missing Authorization vulnerability in wpkoithemes WPKoi Templates for Elementor wpkoi-templates-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPKoi Templates for Elementor: from n/a through <= 3.4.4.

PUBLISHED
Vendor
wpkoithemes
Product
WPKoi Templates for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64273

Missing Authorization vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-official allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email marketing for WordPress by GetResponse Official: from n/a through <= 1.5.3.

PUBLISHED
Vendor
GetResponse
Product
Email marketing for WordPress by GetResponse Official
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64272

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-official allows Retrieve Embedded Sensitive Data.This issue affects Email marketing for WordPress by GetResponse Official: from n/a through <= 1.5.3.

PUBLISHED
Vendor
GetResponse
Product
Email marketing for WordPress by GetResponse Official
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64271

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Request Forgery.This issue affects WP Plugin Manager: from n/a through <= 1.4.7.

PUBLISHED
Vendor
HasThemes
Product
WP Plugin Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64270

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3.

PUBLISHED
Vendor
masteriyo
Product
Masteriyo - LMS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6427

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
1

CVE-2025-64269

Missing Authorization vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 1.2.150.

PUBLISHED
Vendor
EDGARROJAS
Product
WooCommerce PDF Invoice Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64268

Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through <= 1.0.44.

PUBLISHED
Vendor
Arraytics
Product
Timetics
Provider severity
HIGH
Conflicts
0

CVE-2025-64267

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPSwings WooCommerce Ultimate Points And Rewards woocommerce-ultimate-points-and-rewards allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce Ultimate Points And Rewards: from n/a through <= 2.10.2.

PUBLISHED
Vendor
WPSwings
Product
WooCommerce Ultimate Points And Rewards
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64266

Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.4.

PUBLISHED
Vendor
magepeopleteam
Product
Booking and Rental Manager
Provider severity
HIGH
Conflicts
0

CVE-2025-64265

Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.2.

PUBLISHED
Vendor
N-Media
Product
Frontend File Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64264

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman Popup addon for Ninja Forms popup-addon-for-ninja-forms allows Stored XSS.This issue affects Popup addon for Ninja Forms: from n/a through <= 3.5.1.

PUBLISHED
Vendor
Aman
Product
Popup addon for Ninja Forms
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64263

Missing Authorization vulnerability in PluginEver WP Content Pilot wp-content-pilot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Content Pilot: from n/a through <= 2.1.7.

PUBLISHED
Vendor
PluginEver
Product
WP Content Pilot
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64262

Cross-Site Request Forgery (CSRF) vulnerability in ramon fincken Auto Prune Posts auto-prune-posts allows Cross Site Request Forgery.This issue affects Auto Prune Posts: from n/a through <= 3.0.0.

PUBLISHED
Vendor
ramon fincken
Product
Auto Prune Posts
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64261

Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.95.

PUBLISHED
Vendor
codepeople
Product
Appointment Booking Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64260

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Milesi ANAC XML Bandi di Gara avcp allows Reflected XSS.This issue affects ANAC XML Bandi di Gara: from n/a through <= 7.7.

PUBLISHED
Vendor
Marco Milesi
Product
ANAC XML Bandi di Gara
Provider severity
HIGH
Conflicts
0

CVE-2025-6426

The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
HIGH
Conflicts
1

CVE-2025-64259

Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.18.8.

PUBLISHED
Vendor
Jeroen Schmit
Product
Theater for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64258

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Retrieve Embedded Sensitive Data.This issue affects Follow My Blog Post: from n/a through <= 2.3.9.

PUBLISHED
Vendor
wpweb
Product
Follow My Blog Post
Provider severity
HIGH
Conflicts
0

CVE-2025-64257

Missing Authorization vulnerability in Joe Dolson My Tickets my-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Tickets: from n/a through <= 2.1.0.

PUBLISHED
Vendor
Joe Dolson
Product
My Tickets
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64256

Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Folio simple-folio allows Cross Site Request Forgery.This issue affects Simple Folio: from n/a through <= 1.1.0.

PUBLISHED
Vendor
PressTigers
Product
Simple Folio
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64255

Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 8.0.8.

PUBLISHED
Vendor
Bowo
Product
Admin and Site Enhancements (ASE)
Provider severity
LOW
Conflicts
0

CVE-2025-64254

Missing Authorization vulnerability in Ronald Huereca Photo Block photo-block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Block: from n/a through <= 1.5.1.

PUBLISHED
Vendor
Ronald Huereca
Product
Photo Block
Provider severity
LOW
Conflicts
0

CVE-2025-64253

Path Traversal: '.../...//' vulnerability in WordPress.org Health Check & Troubleshooting health-check allows Path Traversal.This issue affects Health Check & Troubleshooting: from n/a through <= 1.7.1.

PUBLISHED
Vendor
WordPress.org
Product
Health Check & Troubleshooting
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64252

Server-Side Request Forgery (SSRF) vulnerability in Marco Milesi ANAC XML Viewer anac-xml-viewer allows Server Side Request Forgery.This issue affects ANAC XML Viewer: from n/a through <= 1.8.2.

PUBLISHED
Vendor
Marco Milesi
Product
ANAC XML Viewer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64251

Missing Authorization vulnerability in azzaroco Ultimate Learning Pro indeed-learning-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Learning Pro: from n/a through <= 3.9.3.

PUBLISHED
Vendor
azzaroco
Product
Ultimate Learning Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64250

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This issue affects Directorist: from n/a through <= 8.6.6.

PUBLISHED
Vendor
wpWax
Product
Directorist
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6425

An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
MEDIUM
Conflicts
1

CVE-2025-64249

Missing Authorization vulnerability in WP-EXPERTS.IN Protect WP Admin protect-wp-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protect WP Admin: from n/a through <= 4.1.

PUBLISHED
Vendor
WP-EXPERTS.IN
Product
Protect WP Admin
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64248

Missing Authorization vulnerability in emarket-design Request a Quote request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Request a Quote: from n/a through <= 2.5.3.

PUBLISHED
Vendor
emarket-design
Product
Request a Quote
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64247

Missing Authorization vulnerability in edmon.parker Read More & Accordion expand-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Read More & Accordion: from n/a through <= 3.5.5.1.

PUBLISHED
Vendor
edmon.parker
Product
Read More & Accordion
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64246

Missing Authorization vulnerability in netopsae Accessibility by AudioEye accessibility-by-audioeye allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility by AudioEye: from n/a through <= 1.0.49.

PUBLISHED
Vendor
netopsae
Product
Accessibility by AudioEye
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64245

Missing Authorization vulnerability in ryanpcmcquen Import external attachments import-external-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Import external attachments: from n/a through <= 1.5.12.

PUBLISHED
Vendor
ryanpcmcquen
Product
Import external attachments
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64244

Missing Authorization vulnerability in Codexpert, Inc Restrict Elementor Widgets, Columns and Sections restrict-elementor-widgets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict Elementor Widgets, Columns and Sections: from n/a through <= 1.12.

PUBLISHED
Vendor
Codexpert, Inc
Product
Restrict Elementor Widgets, Columns and Sections
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64243

Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6.

PUBLISHED
Vendor
e-plugins
Product
Directory Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64242

Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.22.

PUBLISHED
Vendor
Merv Barrett
Product
Easy Property Listings
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64241

Missing Authorization vulnerability in Imtiaz Rayhan WP Coupons and Deals wp-coupons-and-deals allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Coupons and Deals: from n/a through <= 3.2.4.

PUBLISHED
Vendor
Imtiaz Rayhan
Product
WP Coupons and Deals
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64240

Cross-Site Request Forgery (CSRF) vulnerability in freshchat Freshchat freshchat allows Cross Site Request Forgery.This issue affects Freshchat: from n/a through <= 2.3.4.

PUBLISHED
Vendor
freshchat
Product
Freshchat
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6424

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
1

CVE-2025-64239

Cross-Site Request Forgery (CSRF) vulnerability in Yoav Farhi RTL Tester rtl-tester allows Cross Site Request Forgery.This issue affects RTL Tester: from n/a through <= 1.2.

PUBLISHED
Vendor
Yoav Farhi
Product
RTL Tester
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64238

Missing Authorization vulnerability in NicolasKulka WPS Bidouille wps-bidouille allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPS Bidouille: from n/a through <= 1.33.1.

PUBLISHED
Vendor
NicolasKulka
Product
WPS Bidouille
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64237

Cross-Site Request Forgery (CSRF) vulnerability in Graham Quick Interest Slider quick-interest-slider allows Cross Site Request Forgery.This issue affects Quick Interest Slider: from n/a through <= 3.1.5.

PUBLISHED
Vendor
Graham
Product
Quick Interest Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64236

Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.This issue affects Tuturn: from n/a before 3.6.

PUBLISHED
Vendor
AmentoTech
Product
Tuturn
Provider severity
CRITICAL
Conflicts
0

CVE-2025-64235

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn allows Path Traversal.This issue affects Tuturn: from n/a before 3.6.

PUBLISHED
Vendor
AmentoTech
Product
Tuturn
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64234

Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Evergreen Content Poster: from n/a through <= 1.4.5.

PUBLISHED
Vendor
Evergreen Content Poster
Product
Evergreen Content Poster
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64233

Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2.8.

PUBLISHED
Vendor
BoldThemes
Product
Codiqa
Provider severity
CRITICAL
Conflicts
0

CVE-2025-64232

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc Import from YML import-from-yml allows Reflected XSS.This issue affects Import from YML: from n/a through <= 3.1.17.

PUBLISHED
Vendor
icopydoc
Product
Import from YML
Provider severity
HIGH
Conflicts
0