Medium - CVE-2025-6781 - The Copymatic – AI Content Writer & Generator...
The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce...
High - CVE-2025-6813 - The aapanel WP Toolkit plugin for WordPress is...
The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() function in versions 1.0 to 1.1. This makes it possible...
Medium - CVE-2025-7638 - The Forminator Forms – Contact Form, Payment...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and...
Medium - CVE-2025-7648 - The Ruven Themes: Shortcodes plugin for...
The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_button' shortcode in all versions up to, and including, 1.0 due...
Medium - CVE-2025-7660 - The Map My Locations plugin for WordPress is...
The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_locations' shortcode in all versions up to, and including, 1.1 due to...
Medium - CVE-2025-5752 - The Vertical scroll image slideshow gallery...
The Vertical scroll image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 11.1 due to...
Medium - CVE-2025-5754 - The Useful Tab Block – Responsive &...
The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.3.2 due to...
Medium - CVE-2025-5767 - The Crowdfunding for WooCommerce plugin for...
The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 3.1.14 due to insufficient input...
Medium - CVE-2025-5800 - The Testimonial Post type plugin for WordPress...
The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 1.2.1 due to insufficient input...