Medium - CVE-2025-5540 - The Event RSVP and Simple Event Management...
The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to,...
Medium - CVE-2025-5559 - The TimeZoneCalculator plugin for WordPress is...
The TimeZoneCalculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'timezonecalculator_output' shortcode in all versions up to, and including,...
Medium - CVE-2025-5564 - The GC Social Wall plugin for WordPress is...
The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' shortcode in all versions up to, and including, 1.15 due to...
Medium - CVE-2025-5588 - The Image Editor by Pixo plugin for WordPress...
The Image Editor by Pixo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘download’ parameter in all versions up to, and including, 2.3.6 due to insufficient input...
High - CVE-2025-5590 - The Owl carousel responsive plugin for...
The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.9 due to insufficient escaping on the user...
Medium - CVE-2025-5812 - The VG WORT METIS plugin for WordPress is...
The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gutenberg_save_post() function in all versions up to, and...
Medium - CVE-2025-6258 - The WP SoundSystem plugin for WordPress is...
The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 due to insufficient...
Medium - CVE-2025-6290 - The Tournament Bracket Generator plugin for...
The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bracket' shortcode in all versions up to, and including, 1.0.0...
Medium - CVE-2025-6378 - The Responsive Food and Drink Menu plugin for...
The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_pdf_menus shortcode in all versions up to, and including, 2.3 due...
Medium - CVE-2025-6383 - The WP-PhotoNav plugin for WordPress is...
The WP-PhotoNav plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's photonav shortcode in all versions up to, and including, 1.2.2 due to insufficient input...