Medium - CVE-2025-0807 - The CITS Support svg, webp Media and TTF,OTF...
The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to...
Medium - CVE-2025-1311 - The WooCommerce Multivendor Marketplace – REST...
The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in the update_delivery_status() function in all versions up...
High - CVE-2025-2303 - The Block Logic – Full Gutenberg Block Display...
The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 via the block_logic_check_logic...
Medium - CVE-2025-2477 - The CryoKey plugin for WordPress is vulnerable...
The CryoKey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ckemail’ parameter in all versions up to, and including, 2.4 due to insufficient input sanitization and...
Medium - CVE-2025-2478 - The Code Clone plugin for WordPress is...
The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the ‘snippetId’ parameter in all versions up to, and including, 0.9 due to insufficient escaping on the user...
Medium - CVE-2025-2479 - The Easy Custom Admin Bar plugin for WordPress...
The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 1.0 due to insufficient input...
Medium - CVE-2025-2482 - The Gotcha | Gesture-based Captcha plugin for...
The Gotcha | Gesture-based Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menu' parameter in all versions up to, and including, 1.0.0 due to...
Medium - CVE-2025-2484 - The Multi Video Box plugin for WordPress is...
The Multi Video Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'video_id' and 'group_id' parameters in all versions up to, and including, 1.5.2...
Medium - CVE-2024-13666 - The Fluent Forms – Customizable Contact Forms,...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due...
Low - CVE-2025-2616 - A vulnerability classified as problematic has...
A vulnerability classified as problematic has been found in yangyouwang ??? crud ???????? 1.0.0. Affected is an unknown function of the component Role Management Page. The manipulation leads to...