Medium - CVE-2025-6063 - The XiSearch bar plugin for WordPress is...
The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2025-6064 - The WP URL Shortener plugin for WordPress is...
The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the...
Critical - CVE-2025-6065 - The Image Resizer On The Fly plugin for...
The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' task in all versions up to, and...
Medium - CVE-2025-6070 - The Restrict File Access plugin for WordPress...
The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() function. This makes it possible for authenticated...
Medium - CVE-2025-4667 - The Appointment Booking Calendar — Simply...
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Medium - CVE-2025-5238 - The YITH WooCommerce Wishlist plugin for...
The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.5.0 due to insufficient input...
Medium - CVE-2025-5337 - The Slider, Gallery, and Carousel by MetaSlider...
The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to...
NA - CVE-2025-4228 - An incorrect privilege assignment vulnerability...
An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated administrative user to execute certain files available within the Broker VM and...