NA - CVE-2025-48911 - Vulnerability of improper permission assignment...
Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.
Medium - CVE-2025-4964 - The WP Online Users Stats plugin for WordPress...
The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on...
Medium - CVE-2025-4966 - The WP Online Users Stats plugin for WordPress...
The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation within the...
High - CVE-2025-5018 - The Hive Support plugin for WordPress is...
The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and...
Medium - CVE-2025-5019 - The Hive Support | AI-Powered Help Desk, Live...
The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2....
Critical - CVE-2025-5486 - The WP Email Debug plugin for WordPress is...
The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 to 1.1.0. This makes it...