Medium - CVE-2025-5233 - The Color Palette plugin for WordPress is...
The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hex’ parameter in all versions up to, and including, 4.3.2 due to insufficient input sanitization and...
Critical - CVE-2025-5288 - The REST API | Custom API Generator For Cross...
The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the process_handler()...
High - CVE-2025-5491 - Acer ControlCenter contains Remote Code...
Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is...
Medium - CVE-2025-5841 - The ACF Onyx Poll plugin for WordPress is...
The ACF Onyx Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and...
Medium - CVE-2025-5926 - The Link Shield plugin for WordPress is...
The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.4. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2025-5928 - The WP Sliding Login/Dashboard Panel plugin for...
The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce...
Medium - CVE-2025-5930 - The WP2HTML plugin for WordPress is vulnerable...
The WP2HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the save()...
Medium - CVE-2025-5938 - The Digital Marketing and Agency Templates...
The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing...
Medium - CVE-2025-5939 - The Telegram for WP plugin for WordPress is...
The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.1 due to insufficient input sanitization and...
Medium - CVE-2025-5950 - The IndieBlocks plugin for WordPress is...
The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all versions up to, and including, 0.13.2 due to insufficient input sanitization and...