High - CVE-2024-11283 - The WP JobHunt plugin for WordPress is...
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not properly...
Critical - CVE-2024-11284 - The WP JobHunt plugin for WordPress is...
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a...
Critical - CVE-2024-11285 - The WP JobHunt plugin for WordPress is...
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due to the plugin not properly validating a...
Critical - CVE-2024-11286 - The WP JobHunt plugin for WordPress is...
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to the plugin not properly verifying a user's identity prior...
Medium - CVE-2025-0955 - The VidoRev Extensions plugin for WordPress is...
The VidoRev Extensions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'vidorev_import_single_video' AJAX action in all versions up to,...
Medium - CVE-2025-1285 - The Resido - Real Estate WordPress Theme theme...
The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api_key and save_api_key AJAX actions in all...
Medium - CVE-2025-1528 - The Search & Filter Pro plugin for WordPress is...
The Search & Filter Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_meta_values' function in all versions up to, and...
High - CVE-2025-2056 - The WP Ghost (Hide My WP Ghost) – Security &...
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. This makes it...
Medium - CVE-2025-2166 - The CM FAQ – Simplify support with an...
The CM FAQ – Simplify support with an intuitive FAQ management tool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate...