NA - CVE-2025-5992 - When passing values outside of the expected...
When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for example, this can happen when passing a specifically crafted ICC profile to...
Medium - CVE-2025-6716 - The Photos, Files, YouTube, Twitter, Instagram,...
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to...
Medium - CVE-2025-4593 - The WP Register Profile With Shortcode plugin...
The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'rp_user_data' shortcode....
Medium - CVE-2025-5530 - The WPC Smart Compare for WooCommerce plugin...
The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shortcode_btn' shortcode in all versions up to, and...
Medium - CVE-2025-6068 - The FooGallery – Responsive Photo Gallery,...
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` &...
Medium - CVE-2025-6745 - The WoodMart plugin for WordPress is vulnerable...
The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via the woodmart_get_posts_by_query() function due to insufficient restrictions...
High - CVE-2025-7442 - The WPGYM - Wordpress Gym Management System...
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to SQL Injection via several parameters in the MJ_gmgt_delete_class_limit_for_member,...
NA - CVE-2025-6438 - CWE-611: Improper Restriction of XML External...
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection resulting in unauthorized...
Medium - CVE-2025-6838 - The Broken Link Notifier plugin for WordPress...
The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0 via broken links that are later exported. This makes it possible for...
High - CVE-2025-6851 - The Broken Link Notifier plugin for WordPress...
The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_blinks() function which ultimately calls the...