Critical - CVE-2025-1661 - The HUSKY – Products Filter Professional for...
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template'...
High - CVE-2025-2169 - The The WPCS – WordPress Currency Switcher...
The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.0.4. This is due to the...
Medium - CVE-2024-13413 - The ProductDyno plugin for WordPress is...
The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all versions up to, and including, 1.0.24 due to insufficient input sanitization and...
NA - CVE-2024-13574 - The XV Random Quotes WordPress plugin through...
The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
NA - CVE-2024-13580 - The XV Random Quotes WordPress plugin through...
The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack
NA - CVE-2024-13615 - The Social Share Buttons, Social Sharing Icons,...
The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin through 1.3.6 does not sanitise and escape some of its settings, which could...
NA - CVE-2024-13836 - The WP Login Control WordPress plugin through...
The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
NA - CVE-2024-13853 - The SEO Tools WordPress plugin through 4.0.7...
The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against...
NA - CVE-2024-13862 - The S3Bubble Media Streaming...
The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a...