Medium - CVE-2025-7648 - The Ruven Themes: Shortcodes plugin for...
The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_button' shortcode in all versions up to, and including, 1.0 due...
Medium - CVE-2025-7660 - The Map My Locations plugin for WordPress is...
The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_locations' shortcode in all versions up to, and including, 1.1 due to...
Medium - CVE-2025-5752 - The Vertical scroll image slideshow gallery...
The Vertical scroll image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 11.1 due to...
Medium - CVE-2025-5754 - The Useful Tab Block – Responsive &...
The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.3.2 due to...
Medium - CVE-2025-5767 - The Crowdfunding for WooCommerce plugin for...
The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 3.1.14 due to insufficient input...
Medium - CVE-2025-5800 - The Testimonial Post type plugin for WordPress...
The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 1.2.1 due to insufficient input...
Medium - CVE-2025-5811 - The Listly: Listicles For WordPress plugin for...
The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Init() function in all versions up to, and...
Critical - CVE-2025-6222 - The WooCommerce Refund And Exchange with RMA -...
The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
Medium - CVE-2025-6717 - The B1.lt plugin for WordPress is vulnerable to...
The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 2.2.56 due to insufficient escaping on the user supplied...