High - CVE-2025-1509 - The The Show Me The Cookies plugin for...
The The Show Me The Cookies plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0. This is due to the software allowing users to execute an...
High - CVE-2025-1510 - The The Custom Post Type Date Archives plugin...
The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to...
Medium - CVE-2024-12038 - The Post Form – Registration Form – Profile...
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Medium - CVE-2024-12467 - The Pago por Redsys plugin for WordPress is...
The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters' parameter in all versions up to, and including, 1.0.12 due to...
High - CVE-2024-13474 - The LTL Freight Quotes – Purolator Edition...
The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and...
Medium - CVE-2024-13798 - The Post Grid and Gutenberg Blocks –...
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient...
Medium - CVE-2024-13564 - The Rife Elementor Extensions & Templates...
The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and...
High - CVE-2025-1361 - The IP2Location Country Blocker plugin for...
The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init()...
Low - CVE-2025-1553 - A vulnerability was found in pankajindevops...
A vulnerability was found in pankajindevops scale up to 3633544a00245d3df88b6d13d9b3dd0f411be7f6. It has been classified as problematic. Affected is an unknown function of the file /scale/project....
NA - CVE-2025-21704 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: usb: cdc-acm: Check control transfer buffer size before access If the first fragment is shorter than struct...