CVE-2025-30977 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chaport Live Chat WP Live Chat + Chatbots Plugin for WordPress – Chaport allows Stored XSS. This issue affects WP Live Chat + Chatbots Plugin for WordPress – Chaport: from n/a through 1.1.5.
CVSS: MEDIUM (5.9) EPSS Score: 0.03%
June 6th, 2025 (about 1 month ago)
|
CVE-2025-30976 |
Description: Server-Side Request Forgery (SSRF) vulnerability in wpdive Nexa Blocks allows Server Side Request Forgery. This issue affects Nexa Blocks: from n/a through 1.1.0.
CVSS: MEDIUM (4.9) EPSS Score: 0.03%
June 6th, 2025 (about 1 month ago)
|
CVE-2025-30974 |
Description: Missing Authorization vulnerability in Akhtarujjaman Shuvo Post Grid Master allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post Grid Master: from n/a through 3.4.13.
CVSS: MEDIUM (4.3) EPSS Score: 0.03%
June 6th, 2025 (about 1 month ago)
|
CVE-2025-30968 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in jokerbr313 Advanced Post List allows Cross Site Request Forgery. This issue affects Advanced Post List: from n/a through 0.5.6.2.
CVSS: MEDIUM (5.4) EPSS Score: 0.02%
June 6th, 2025 (about 1 month ago)
|
CVE-2025-30958 |
Description: Missing Authorization vulnerability in onOffice GmbH onOffice for WP-Websites allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects onOffice for WP-Websites: from n/a through 5.7.
CVSS: MEDIUM (5.4) EPSS Score: 0.04%
June 6th, 2025 (about 1 month ago)
|
CVE-2025-30957 |
Description: Missing Authorization vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Activity Plus Reloaded for BuddyPress: from n/a through 1.1.2.
CVSS: MEDIUM (5.4) EPSS Score: 0.04%
June 6th, 2025 (about 1 month ago)
|
CVE-2025-30956 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in Booqable Rental Software Booqable Rental allows Cross Site Request Forgery. This issue affects Booqable Rental: from n/a through 2.4.20.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
June 6th, 2025 (about 1 month ago)
|
CVE-2025-30954 |
Description: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin allows Phishing. This issue affects WP Gravity Forms Constant Contact Plugin: from n/a through 1.1.0.
CVSS: MEDIUM (4.7) EPSS Score: 0.03%
June 6th, 2025 (about 1 month ago)
|
CVE-2025-30953 |
Description: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Salesforce allows Phishing. This issue affects WP Gravity Forms Salesforce: from n/a through 1.4.7.
CVSS: MEDIUM (4.7) EPSS Score: 0.03%
June 6th, 2025 (about 1 month ago)
|
CVE-2025-30952 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdive Nexa Blocks allows Stored XSS. This issue affects Nexa Blocks: from n/a through 1.1.0.
CVSS: MEDIUM (6.5) EPSS Score: 0.03%
June 6th, 2025 (about 1 month ago)
|