Medium - CVE-2024-13411 - The Zapier for WordPress plugin for WordPress...
The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5.1 via the updated_user() function. This makes it possible for...
High - CVE-2024-13889 - The WordPress Importer plugin for WordPress is...
The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of untrusted input in the...
Medium - CVE-2025-1312 - The Ultimate Blocks – WordPress Blocks Plugin...
The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttonTextColor’ parameter in all versions up to, and including, 3.2.7...
Medium - CVE-2025-1769 - The Product Import Export for WooCommerce –...
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.0 via the...
Low - CVE-2025-1911 - The Product Import Export for WooCommerce –...
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the...
High - CVE-2025-1912 - The Product Import Export for WooCommerce –...
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the...
High - CVE-2025-1913 - The Product Import Export for WooCommerce –...
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via...
High - CVE-2025-2110 - The WP Compress – Instant Performance & Speed...
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its...
Medium - CVE-2025-2228 - The Responsive Addons for Elementor – Free...
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...