Medium - CVE-2025-5564 - The GC Social Wall plugin for WordPress is...
The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' shortcode in all versions up to, and including, 1.15 due to...
Medium - CVE-2025-5588 - The Image Editor by Pixo plugin for WordPress...
The Image Editor by Pixo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘download’ parameter in all versions up to, and including, 2.3.6 due to insufficient input...
High - CVE-2025-5590 - The Owl carousel responsive plugin for...
The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.9 due to insufficient escaping on the user...
Medium - CVE-2025-5812 - The VG WORT METIS plugin for WordPress is...
The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gutenberg_save_post() function in all versions up to, and...
Medium - CVE-2025-6258 - The WP SoundSystem plugin for WordPress is...
The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 due to insufficient...
Medium - CVE-2025-6290 - The Tournament Bracket Generator plugin for...
The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bracket' shortcode in all versions up to, and including, 1.0.0...
Medium - CVE-2025-6378 - The Responsive Food and Drink Menu plugin for...
The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_pdf_menus shortcode in all versions up to, and including, 2.3 due...
Medium - CVE-2025-6383 - The WP-PhotoNav plugin for WordPress is...
The WP-PhotoNav plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's photonav shortcode in all versions up to, and including, 1.2.2 due to insufficient input...
Medium - CVE-2025-6538 - The Post Rating and Review plugin for WordPress...
The Post Rating and Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.3.4 due to insufficient input...
Medium - CVE-2025-5275 - The Charitable – Donation Plugin for WordPress...
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the privacy settings fields in all...