Medium - CVE-2025-4571 - The GiveWP – Donation Plugin and Fundraising...
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability check on the...
Medium - CVE-2025-4965 - The WPBakery Page Builder for WordPress plugin...
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Builder feature in all versions up to, and including, 8.4.1 due...
NA - CVE-2025-31698 - ACL configured in ip_allow.config or...
ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP...
NA - CVE-2025-49763 - ESI plugin does not have the limit for maximum...
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin...
High - CVE-2025-5071 - The AI Engine plugin for WordPress is...
The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs_MCP::can_access_mcp'...
Medium - CVE-2025-5234 - The Gutenverse News plugin for WordPress is...
The Gutenverse News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘elementId’ parameter in all versions up to, and including, 1.0.4 due to insufficient input...
NA - CVE-2025-32896 - # Summary
Unauthorized users can perform...
# Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access...
High - CVE-2025-6019 - A Local Privilege Escalation (LPE)...
A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the...