CVE-2025-2789 |
Description: The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_table_rate_shipping_row function in all versions up to, and including, 4.2.19. This makes it possible for unauthenticated attackers to delete Table Rates that can impact the shipping cost calculations.
CVSS: MEDIUM (5.3) EPSS Score: 0.04%
April 5th, 2025 (15 days ago)
|
CVE-2025-1233 |
Description: The Lafka Plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_options_upload' AJAX function in all versions up to, and including, 7.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the theme option that overrides the site.
CVSS: MEDIUM (4.3) EPSS Score: 0.03%
April 5th, 2025 (15 days ago)
|
CVE-2025-0839 |
Description: The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.4) EPSS Score: 0.03%
April 5th, 2025 (15 days ago)
|
CVE-2025-2544 |
Description: The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
CVSS: MEDIUM (6.4) EPSS Score: 0.04%
April 5th, 2025 (15 days ago)
|
CVE-2025-2889 |
Description: The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.4) EPSS Score: 0.03%
April 5th, 2025 (16 days ago)
|
CVE-2025-32280 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager allows Cross Site Request Forgery. This issue affects WP Project Manager: from n/a through 2.6.22.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
April 4th, 2025 (16 days ago)
|
CVE-2025-32278 |
WordPress Table Block by RioVizual plugin <= 2.1.7 - Cross Site Request Forgery (CSRF) vulnerability
Description: Cross-Site Request Forgery (CSRF) vulnerability in wprio Table Block by RioVizual allows Cross Site Request Forgery. This issue affects Table Block by RioVizual: from n/a through 2.1.7.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
April 4th, 2025 (16 days ago)
|
CVE-2025-32277 |
Description: Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 3.8211.
CVSS: MEDIUM (4.3) EPSS Score: 0.03%
April 4th, 2025 (16 days ago)
|
CVE-2025-32276 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z allows Cross Site Request Forgery. This issue affects Administrator Z: from n/a through 2025.03.04.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
April 4th, 2025 (16 days ago)
|
CVE-2025-32274 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB allows Cross Site Request Forgery. This issue affects WP w3all phpBB: from n/a through 2.9.2.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
April 4th, 2025 (16 days ago)
|