Medium - CVE-2025-4187 - The UserPro - Community and User Profile...
The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 via the userpro_fbconnect()...
High - CVE-2025-4200 - The Zagg - Electronics & Accessories...
The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.1 via the load_view() function...
Medium - CVE-2025-4216 - The DIOT SCADA with MQTT plugin for WordPress...
The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and including, 1.0.5.1 due to...
Medium - CVE-2025-4592 - The AI Image Lab – Free AI Image Generator...
The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce...
Medium - CVE-2025-5336 - The Click to Chat plugin for WordPress is...
The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter in all versions up to, and including, 4.22 to insufficient input sanitization...
Medium - CVE-2025-5589 - The StreamWeasels Kick Integration plugin for...
The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 due...
Medium - CVE-2025-6040 - The Easy Flashcards plugin for WordPress is...
The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2025-6055 - The Zen Sticky Social plugin for WordPress is...
The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2025-6061 - The kk Youtube Video plugin for WordPress is...
The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcode in all versions up to, and including, 0.2 due to...
Medium - CVE-2025-6062 - The Yougler Blogger Profile Page plugin for...
The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due to missing or incorrect nonce validation...