Critical - CVE-2025-4334 - The Simple User Registration plugin for...
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that...
Medium - CVE-2025-5488 - The WP Masonry & Infinite Scroll plugin for...
The WP Masonry & Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wmis' shortcode in all versions up to, and including, 2.2 due to...
Medium - CVE-2025-5535 - The e.nigma buttons plugin for WordPress is...
The e.nigma buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 1.1.3 due to...
Medium - CVE-2025-5540 - The Event RSVP and Simple Event Management...
The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to,...
Medium - CVE-2025-5559 - The TimeZoneCalculator plugin for WordPress is...
The TimeZoneCalculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'timezonecalculator_output' shortcode in all versions up to, and including,...
Medium - CVE-2025-5564 - The GC Social Wall plugin for WordPress is...
The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' shortcode in all versions up to, and including, 1.15 due to...
Medium - CVE-2025-5588 - The Image Editor by Pixo plugin for WordPress...
The Image Editor by Pixo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘download’ parameter in all versions up to, and including, 2.3.6 due to insufficient input...
High - CVE-2025-5590 - The Owl carousel responsive plugin for...
The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.9 due to insufficient escaping on the user...
Medium - CVE-2025-5812 - The VG WORT METIS plugin for WordPress is...
The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gutenberg_save_post() function in all versions up to, and...
Medium - CVE-2025-6258 - The WP SoundSystem plugin for WordPress is...
The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 due to insufficient...