Medium - CVE-2025-4592 - The AI Image Lab – Free AI Image Generator...
The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce...
Medium - CVE-2025-5336 - The Click to Chat plugin for WordPress is...
The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter in all versions up to, and including, 4.22 to insufficient input sanitization...
Medium - CVE-2025-5589 - The StreamWeasels Kick Integration plugin for...
The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 due...
Medium - CVE-2025-6040 - The Easy Flashcards plugin for WordPress is...
The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2025-6055 - The Zen Sticky Social plugin for WordPress is...
The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2025-6061 - The kk Youtube Video plugin for WordPress is...
The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcode in all versions up to, and including, 0.2 due to...
Medium - CVE-2025-6062 - The Yougler Blogger Profile Page plugin for...
The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due to missing or incorrect nonce validation...
Medium - CVE-2025-6063 - The XiSearch bar plugin for WordPress is...
The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2025-6064 - The WP URL Shortener plugin for WordPress is...
The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the...
Critical - CVE-2025-6065 - The Image Resizer On The Fly plugin for...
The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' task in all versions up to, and...