High - CVE-2025-2056 - The WP Ghost (Hide My WP Ghost) – Security &...
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. This makes it...
Medium - CVE-2025-2166 - The CM FAQ – Simplify support with an...
The CM FAQ – Simplify support with an intuitive FAQ management tool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate...
High - CVE-2024-13376 - The Industrial theme for WordPress is...
The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the...
High - CVE-2024-13913 - The InstaWP Connect – 1-click WP Staging &...
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.0.83. This is due to missing or...
High - CVE-2025-0952 - The Eco Nature - Environment & Ecology...
The Eco Nature - Environment & Ecology WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check...
High - CVE-2025-1764 - The LoginPress | wp-login Custom Login Page...
The LoginPress | wp-login Custom Login Page Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.1. This is due to missing or...
High - CVE-2025-2103 - The SoundRise Music plugin for WordPress is...
The SoundRise Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on theironMusic_ajax() function...
Medium - CVE-2025-2289 - The Zegen - Church WordPress Theme theme for...
The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX endpoints in all versions up to, and including, 1.1.9....
Critical - CVE-2024-13824 - The CiyaShop - Multipurpose WooCommerce Theme...
The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.19.0 via deserialization of untrusted input in the...
High - CVE-2025-2221 - The WPCOM Member plugin for WordPress is...
The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in all versions up to, and including, 1.7.6 due to insufficient escaping on the user...