Medium - CVE-2025-5752 - The Vertical scroll image slideshow gallery...
The Vertical scroll image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 11.1 due to...
Medium - CVE-2025-5754 - The Useful Tab Block – Responsive &...
The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.3.2 due to...
Medium - CVE-2025-5767 - The Crowdfunding for WooCommerce plugin for...
The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 3.1.14 due to insufficient input...
Medium - CVE-2025-5800 - The Testimonial Post type plugin for WordPress...
The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 1.2.1 due to insufficient input...
Medium - CVE-2025-5811 - The Listly: Listicles For WordPress plugin for...
The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Init() function in all versions up to, and...
Critical - CVE-2025-6222 - The WooCommerce Refund And Exchange with RMA -...
The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
Medium - CVE-2025-6717 - The B1.lt plugin for WordPress is vulnerable to...
The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 2.2.56 due to insufficient escaping on the user supplied...
High - CVE-2025-6718 - The B1.lt plugin for WordPress is vulnerable to...
The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX action in all versions up to, and including, 2.2.56. This makes it possible...
Medium - CVE-2025-6719 - The Terms descriptions plugin for WordPress is...
The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and...