NA - CVE-2025-6200 - The GeoDirectory WordPress plugin before...
The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could...
NA - CVE-2025-30023 - The communication protocol used between client...
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
NA - CVE-2025-2942 - The Order Delivery Date WordPress plugin before...
The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such...
NA - CVE-2025-5028 - Installation file of ESET security products on...
Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so.
Critical - CVE-2025-5392 - The GB Forms DB plugin for WordPress is...
The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 via the gbfdb_talk_to_front() function. This is due to the function accepting...
NA - CVE-2025-5992 - When passing values outside of the expected...
When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for example, this can happen when passing a specifically crafted ICC profile to...
Medium - CVE-2025-6716 - The Photos, Files, YouTube, Twitter, Instagram,...
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to...