Medium - CVE-2025-5019 - The Hive Support | AI-Powered Help Desk, Live...
The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2....
Critical - CVE-2025-5486 - The WP Email Debug plugin for WordPress is...
The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 to 1.1.0. This makes it...
Medium - CVE-2025-5533 - The Knowledge Base plugin for WordPress is...
The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kbalert' shortcode in all versions up to, and including, 2.3.0 due to...
Medium - CVE-2025-5534 - The ESV Bible Shortcode for WordPress plugin...
The ESV Bible Shortcode for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'esv' shortcode in all versions up to, and including, 1.0.2...
Medium - CVE-2025-5536 - The Freemind Viewer plugin for WordPress is...
The Freemind Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'freemind' shortcode in all versions up to, and including, 1.0 due to...
Medium - CVE-2025-5538 - The BNS Featured Category plugin for WordPress...
The BNS Featured Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bnsfc' shortcode in all versions up to, and including, 2.8.2 due to...
Medium - CVE-2025-5541 - The Runners Log plugin for WordPress is...
The Runners Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'runnerslog' shortcode in all versions up to, and including, 3.9.2 due to...
Medium - CVE-2025-5563 - The WP-Addpub plugin for WordPress is...
The WP-Addpub plugin for WordPress is vulnerable to SQL Injection via the 'wp-addpub' shortcode in all versions up to, and including, 1.2.8 due to insufficient escaping on the user...
Medium - CVE-2025-5565 - The Hide It plugin for WordPress is vulnerable...
The Hide It plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hideit' shortcode in all versions up to, and including, 1.0.1 due to insufficient...
Medium - CVE-2025-5586 - The WordPress Ajax Load More and Infinite...
The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.0 due to...