High - CVE-2025-0956 - The WooCommerce Recover Abandoned Cart plugin...
The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.3.0 via deserialization of untrusted input from the...
Critical - CVE-2025-1515 - The WP Real Estate Manager plugin for WordPress...
The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.8. This is due to insufficient identity verification on the LinkedIn...
NA - CVE-2025-25015 - Prototype pollution in Kibana leads to...
Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by...
Medium - CVE-2024-11153 - The Content Control – The Ultimate Content...
The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Critical - CVE-2024-11951 - The Homey Login Register plugin for WordPress...
The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. This is due to the plugin allowing users who are registering new...
Critical - CVE-2024-12281 - The Homey theme for WordPress is vulnerable to...
The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is due to the plugin allowing users who are registering new accounts to set...
Medium - CVE-2024-12650 - An attacker with low privileges can manipulate...
An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a crash of the application but it does not...
Medium - CVE-2024-13423 - The Sparkling theme for WordPress is vulnerable...
The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and...
High - CVE-2024-13471 - The DesignThemes Core Features plugin for...
The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to,...
Medium - CVE-2025-1463 - The Spreadsheet Integration plugin for...
The Spreadsheet Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.2. This is due to improper nonce validation within the...