Medium - CVE-2024-13737 - The Motors – Car Dealer, Classifieds & Listing...
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and...
Medium - CVE-2024-13739 - The Newsletters plugin for WordPress is...
The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and...
Medium - CVE-2025-0723 - The ProfileGrid – User Profiles, Groups and...
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and...
High - CVE-2025-0724 - The ProfileGrid – User Profiles, Groups and...
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted...
Medium - CVE-2025-1408 - The ProfileGrid – User Profiles, Groups and...
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
Medium - CVE-2024-13768 - The CITS Support svg, webp Media and TTF,OTF...
The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to...
Medium - CVE-2024-13856 - The Your Friendly Drag and Drop Page Builder —...
The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.10 via the...
Medium - CVE-2025-0807 - The CITS Support svg, webp Media and TTF,OTF...
The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to...
Medium - CVE-2025-1311 - The WooCommerce Multivendor Marketplace – REST...
The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in the update_delivery_status() function in all versions up...
High - CVE-2025-2303 - The Block Logic – Full Gutenberg Block Display...
The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 via the block_logic_check_logic...