Medium - CVE-2025-5811 - The Listly: Listicles For WordPress plugin for...
The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Init() function in all versions up to, and...
Critical - CVE-2025-6222 - The WooCommerce Refund And Exchange with RMA -...
The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
Medium - CVE-2025-6717 - The B1.lt plugin for WordPress is vulnerable to...
The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 2.2.56 due to insufficient escaping on the user supplied...
High - CVE-2025-6718 - The B1.lt plugin for WordPress is vulnerable to...
The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX action in all versions up to, and including, 2.2.56. This makes it possible...
Medium - CVE-2025-6719 - The Terms descriptions plugin for WordPress is...
The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and...
Medium - CVE-2025-6726 - The Block Editor Gallery Slider plugin for...
The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the classic_gallery_slider_options() function in all...
Critical - CVE-2025-7643 - The Attachment Manager plugin for WordPress is...
The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handle_actions() function in all versions up to, and including,...
High - CVE-2025-7438 - The MasterStudy LMS Pro plugin for WordPress is...
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_activate_plugin' function in all versions...
Medium - CVE-2025-7772 - The Malcure Malware Scanner — #1 Toolset for...
The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 16.8 via the...
NA - CVE-2024-27779 - An insufficient session expiration...
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator...