NA - CVE-2025-36630 - In Tenable Nessus versions prior to 10.8.5 on a...
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
High - CVE-2025-5692 - The Lead Form Data Collection to CRM plugin for...
The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the...
Medium - CVE-2024-11405 - The WP Front-end login and register plugin for...
The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email and wpmp_reset_password_token parameters in all versions up to, and including,...
High - CVE-2025-3848 - The Download Manager and Payment Form WordPress...
The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 1.1.0 to 2.7.13. This is due to the...
High - CVE-2025-4380 - The Ads Pro Plugin - Multi-Purpose WordPress...
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the...
High - CVE-2025-4381 - The Ads Pro Plugin - Multi-Purpose WordPress...
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘$id’ variable of the getSpace() function in all versions up to, and...
Low - CVE-2025-4654 - The Soumettre.fr plugin for WordPress is...
The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper authorization checks on the make_signature function in all versions up to, and...
Critical - CVE-2025-4689 - The Ads Pro Plugin - Multi-Purpose WordPress...
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Code Execution in all versions up to, and...