Medium - CVE-2025-2939 - The Ninja Tables – Easy Data Table Builder...
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the...
Medium - CVE-2025-4047 - The Broken Link Checker plugin for WordPress is...
The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the ajax_full_status and ajax_dashboard_status functions in all versions...
High - CVE-2025-4224 - The wpForo + wpForo Advanced Attachments plugin...
The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient...
Critical - CVE-2025-4797 - The Golo - City Travel Guide WordPress Theme...
The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is due to the plugin...