High - CVE-2025-1513 - The Photos, Files, YouTube, Twitter, Instagram,...
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plugin for WordPress is vulnerable to Stored...
Medium - CVE-2025-0764 - The wpForo Forum plugin for WordPress is...
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up...
Medium - CVE-2025-1405 - The Product Catalog Simple plugin for WordPress...
The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_products shortcode in all versions up to, and including, 1.7.11 due to...
Medium - CVE-2025-1571 - The Exclusive Addons for Elementor plugin for...
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Image Comparison Widgets in all versions up to, and...
Medium - CVE-2025-1572 - The KiviCare – Clinic & Patient Management...
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions up to, and including, 3.6.7 due to insufficient...
Medium - CVE-2024-13469 - The Pricing Table by PickPlugins plugin for...
The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link in all versions up to, and including, 1.12.10 due to insufficient input...
Medium - CVE-2024-13638 - The Order Attachments for WooCommerce plugin...
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' directory. This...
Medium - CVE-2024-13716 - The Forex Calculators plugin for WordPress is...
The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_settings_callback() function in all versions up to, and...
High - CVE-2024-13831 - The Tabs for WooCommerce plugin for WordPress...
The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input in the...
Medium - CVE-2024-13832 - The Ultra Addons Lite for Elementor plugin for...
The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.8 via the 'ut_elementor' shortcode due to...