High - CVE-2025-1653 - The Directory Listings WordPress plugin –...
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.7. This is due to the...
High - CVE-2025-1657 - The Directory Listings WordPress plugin –...
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection due to a missing capability check on the...
Medium - CVE-2024-12336 - The WC Affiliate – A Complete WooCommerce...
The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'export_all_data'...
Medium - CVE-2024-13847 - The Portfolio and Projects plugin for WordPress...
The Portfolio and Projects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.3 due to insufficient input sanitization...
High - CVE-2025-1667 - The School Management System – WPSchoolPress...
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wpsp_UpdateTeacher() function in all versions up to,...
Medium - CVE-2025-1668 - The School Management System – WPSchoolPress...
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a missing capability check on the wpsp_DeleteUser() function in all versions up to,...
Medium - CVE-2025-1669 - The School Management System – WPSchoolPress...
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' action in all versions up to, and including, 2.2.16 due to...
Medium - CVE-2025-1670 - The School Management System – WPSchoolPress...
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.16 due to insufficient...
Medium - CVE-2025-2163 - The Zoorum Comments plugin for WordPress is...
The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2025-2164 - The pixelstats plugin for WordPress is...
The pixelstats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' and 'sortby' parameters in all versions up to, and including, 0.8.2 due to...