High - CVE-2025-1970 - The Export and Import Users and Customers...
The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes...
High - CVE-2025-1971 - The Export and Import Users and Customers...
The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the...
Low - CVE-2025-1972 - The Export and Import Users and Customers...
The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up...
Medium - CVE-2025-1973 - The Export and Import Users and Customers...
The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible...
Medium - CVE-2025-2331 - The GiveWP – Donation Plugin and Fundraising...
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.22.1 via a misconfigured...
Medium - CVE-2025-2577 - The Bitspecter Suite plugin for WordPress is...
The Bitspecter Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and...
NA - CVE-2025-26796 - ** UNSUPPORTED WHEN ASSIGNED ** Improper...
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozie: all...
High - CVE-2025-2186 - The Recover WooCommerce Cart Abandonment,...
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the ‘automationId’ parameter in all...
Low - CVE-2025-2617 - A vulnerability classified as problematic was...
A vulnerability classified as problematic was found in yangyouwang ??? crud ???????? 1.0.0. Affected by this vulnerability is an unknown functionality of the component Department Page. The...
Critical - CVE-2025-2618 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler....