Low - CVE-2025-7767 - A vulnerability, which was classified as...
A vulnerability, which was classified as problematic, has been found in PHPGurukul Art Gallery Management System 1.1. Affected by this issue is some unknown functionality of the file...
Medium - CVE-2025-7431 - The Knowledge Base plugin for WordPress is...
The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization...
High - CVE-2025-3740 - The School Management System for Wordpress...
The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 via the 'page' parameter. This makes it...
Medium - CVE-2025-5816 - The Plugin Pengiriman WooCommerce Kurir...
The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.0 via the...
Medium - CVE-2025-6053 - The Zuppler Online Ordering plugin for...
The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2025-6781 - The Copymatic – AI Content Writer & Generator...
The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce...
High - CVE-2025-6813 - The aapanel WP Toolkit plugin for WordPress is...
The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() function in versions 1.0 to 1.1. This makes it possible...
Medium - CVE-2025-7638 - The Forminator Forms – Contact Form, Payment...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and...
Medium - CVE-2025-7648 - The Ruven Themes: Shortcodes plugin for...
The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_button' shortcode in all versions up to, and including, 1.0 due...
Medium - CVE-2025-7660 - The Map My Locations plugin for WordPress is...
The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_locations' shortcode in all versions up to, and including, 1.1 due to...