CVE-2025-2544 |
Description: The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
CVSS: MEDIUM (6.4) EPSS Score: 0.04%
April 5th, 2025 (18 days ago)
|
CVE-2025-0810 |
Description: The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.5. This is due to missing or incorrect nonce validation on the addNewButtons() function. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS: HIGH (7.5) EPSS Score: 0.02%
April 5th, 2025 (18 days ago)
|
CVE-2024-13604 |
Description: The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.4 via the 'kbs' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/kbs directory which can contain file attachments included in support tickets. The vulnerability was partially patched in version 1.7.3.2.
CVSS: HIGH (7.5) EPSS Score: 0.05%
April 5th, 2025 (18 days ago)
|
CVE-2025-2889 |
Description: The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.4) EPSS Score: 0.03%
April 5th, 2025 (18 days ago)
|
CVE-2025-32280 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager allows Cross Site Request Forgery. This issue affects WP Project Manager: from n/a through 2.6.22.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
April 4th, 2025 (18 days ago)
|
CVE-2025-32278 |
WordPress Table Block by RioVizual plugin <= 2.1.7 - Cross Site Request Forgery (CSRF) vulnerability
Description: Cross-Site Request Forgery (CSRF) vulnerability in wprio Table Block by RioVizual allows Cross Site Request Forgery. This issue affects Table Block by RioVizual: from n/a through 2.1.7.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
April 4th, 2025 (18 days ago)
|
CVE-2025-32277 |
Description: Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 3.8211.
CVSS: MEDIUM (4.3) EPSS Score: 0.03%
April 4th, 2025 (18 days ago)
|
CVE-2025-32276 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z allows Cross Site Request Forgery. This issue affects Administrator Z: from n/a through 2025.03.04.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
April 4th, 2025 (18 days ago)
|
CVE-2025-32274 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB allows Cross Site Request Forgery. This issue affects WP w3all phpBB: from n/a through 2.9.2.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
April 4th, 2025 (18 days ago)
|
CVE-2025-32273 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in freetobook Freetobook Responsive Widget allows Cross Site Request Forgery. This issue affects Freetobook Responsive Widget: from n/a through 1.1.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
April 4th, 2025 (18 days ago)
|