Medium - CVE-2025-5956 - The WP Human Resource Management plugin for...
The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authorization within the ajax_delete_employee() function in versions 2.0.0 through...
Medium - CVE-2025-6039 - The ProcessingJS for WordPress plugin for...
The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4wp' shortcode in all versions up to, and including, 1.2.2 due...
Medium - CVE-2025-6041 - The yContributors plugin for WordPress is...
The yContributors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect nonce validation on the...
High - CVE-2025-6238 - The AI Engine plugin for WordPress is...
The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' parameter is missing validation...
High - CVE-2025-6586 - The Download Plugin plugin for WordPress is...
The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwap_plugin_locInstall function in all versions up to, and including,...
Medium - CVE-2025-6729 - The PayMaster for WooCommerce plugin for...
The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.4.31 via the 'wp_ajax_paym_status' AJAX action This...
Medium - CVE-2025-6739 - The WPQuiz plugin for WordPress is vulnerable...
The WPQuiz plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'wpquiz' shortcode in all versions up to, and including, 0.4.2 due to insufficient...
High - CVE-2025-6782 - The GoZen Forms plugin for WordPress is...
The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the dirGZActiveForm() function in all versions up to, and including, 1.1.5 due to...
High - CVE-2025-6783 - The GoZen Forms plugin for WordPress is...
The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() function in all versions up to, and including, 1.1.5 due to insufficient...
Medium - CVE-2025-6786 - The DocCheck Login plugin for WordPress is...
The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, 1.1.5. This is due to plugin redirecting a user to login on a password...