High - CVE-2025-0724 - The ProfileGrid – User Profiles, Groups and...
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted...
Medium - CVE-2025-1408 - The ProfileGrid – User Profiles, Groups and...
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
Medium - CVE-2024-13768 - The CITS Support svg, webp Media and TTF,OTF...
The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to...
Medium - CVE-2024-13856 - The Your Friendly Drag and Drop Page Builder —...
The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.10 via the...
Medium - CVE-2025-0807 - The CITS Support svg, webp Media and TTF,OTF...
The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to...
Medium - CVE-2025-1311 - The WooCommerce Multivendor Marketplace – REST...
The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in the update_delivery_status() function in all versions up...
High - CVE-2025-2303 - The Block Logic – Full Gutenberg Block Display...
The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 via the block_logic_check_logic...
Medium - CVE-2025-2477 - The CryoKey plugin for WordPress is vulnerable...
The CryoKey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ckemail’ parameter in all versions up to, and including, 2.4 due to insufficient input sanitization and...
Medium - CVE-2025-2478 - The Code Clone plugin for WordPress is...
The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the ‘snippetId’ parameter in all versions up to, and including, 0.9 due to insufficient escaping on the user...
Medium - CVE-2025-2479 - The Easy Custom Admin Bar plugin for WordPress...
The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 1.0 due to insufficient input...