Medium - CVE-2025-22622 - Age Verification for your checkout page. Verify...
Age Verification for your checkout page. Verify your customer's identity 1.20.0 was found to be vulnerable. The web application dynamically generates web content without validating the source...
Medium - CVE-2025-1441 - The Royal Elementor Addons and Templates plugin...
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce...
NA - CVE-2024-12173 - The Master Slider WordPress plugin before...
The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site...
Medium - CVE-2024-13799 - The User Private Files – File Upload & Download...
The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions...
Medium - CVE-2025-1065 - The Visualizer: Tables and Charts Manager for...
The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature in all versions up to,...
NA - CVE-2025-22888 - Movable Type contains a stored cross-site...
Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If exploited, an arbitrary script may be executed on a logged-in user's web...
NA - CVE-2025-24841 - Movable Type contains a stored cross-site...
Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as a rich text editor and an arbitrary script may...
NA - CVE-2025-25054 - Movable Type contains a reflected cross-site...
Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a crafted page while...
Medium - CVE-2024-11335 - The UltraEmbed – Advanced Iframe Plugin For...
The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframe'...