High - CVE-2024-11087 - The miniOrange Social Login and Register...
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9....
High - CVE-2024-13908 - The SMTP by BestWebSoft plugin for WordPress is...
The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and...
Medium - CVE-2024-10321 - The All-in-One Addons for Elementor – WidgetKit...
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.4 in...
Medium - CVE-2024-13816 - The Aiomatic - Automatic AI Content Writer &...
The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a...
High - CVE-2024-13882 - The Aiomatic - Automatic AI Content Writer &...
The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in...
Critical - CVE-2025-0177 - The Javo Core plugin for WordPress is...
The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts...
Medium - CVE-2025-1287 - The The Plus Addons for Elementor – Elementor...
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown, Syntax...
High - CVE-2024-13359 - The Product Input Fields for WooCommerce plugin...
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta()...
Medium - CVE-2025-1322 - The WP-Recall – Registration, Profile, Commerce...
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the 'feed' shortcode...
High - CVE-2025-1323 - The WP-Recall – Registration, Profile, Commerce...
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due...