Medium - CVE-2025-5812 - The VG WORT METIS plugin for WordPress is...
The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gutenberg_save_post() function in all versions up to, and...
Medium - CVE-2025-6258 - The WP SoundSystem plugin for WordPress is...
The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 due to insufficient...
Medium - CVE-2025-6290 - The Tournament Bracket Generator plugin for...
The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bracket' shortcode in all versions up to, and including, 1.0.0...
Medium - CVE-2025-6378 - The Responsive Food and Drink Menu plugin for...
The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_pdf_menus shortcode in all versions up to, and including, 2.3 due...
Medium - CVE-2025-6383 - The WP-PhotoNav plugin for WordPress is...
The WP-PhotoNav plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's photonav shortcode in all versions up to, and including, 1.2.2 due to insufficient input...
Medium - CVE-2025-6538 - The Post Rating and Review plugin for WordPress...
The Post Rating and Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.3.4 due to insufficient input...
Medium - CVE-2025-5275 - The Charitable – Donation Plugin for WordPress...
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the privacy settings fields in all...
Medium - CVE-2025-5813 - The Amazon Products to WooCommerce plugin for...
The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function in...
Medium - CVE-2025-5929 - The The Countdown plugin for WordPress is...
The The Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘clientId’ parameter in all versions up to, and including, 2.0.1 due to insufficient input sanitization...
Medium - CVE-2025-5932 - The Homerunner plugin for WordPress is...
The Homerunner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.29. This is due to missing or incorrect nonce validation on the...