Medium - CVE-2025-6059 - The Seraphinite Accelerator plugin for...
The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing or incorrect nonce validation on...
High - CVE-2025-3234 - The File Manager Pro – Filester plugin for...
The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.8.8. This makes it possible...
High - CVE-2025-5487 - The AutomatorWP – Automator plugin for no-code...
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions...
Medium - CVE-2025-4187 - The UserPro - Community and User Profile...
The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 via the userpro_fbconnect()...
High - CVE-2025-4200 - The Zagg - Electronics & Accessories...
The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.1 via the load_view() function...
Medium - CVE-2025-4216 - The DIOT SCADA with MQTT plugin for WordPress...
The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and including, 1.0.5.1 due to...
Medium - CVE-2025-4592 - The AI Image Lab – Free AI Image Generator...
The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce...