Medium - CVE-2025-6720 - The Vchasno Kasa plugin for WordPress is...
The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in all versions up to, and including, 1.0.3. This...
Medium - CVE-2025-6721 - The Vchasno Kasa plugin for WordPress is...
The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mrkv_vchasno_kasa_wc_do_metabox_action() function in all versions up to,...
NA - CVE-2025-38350 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: net/sched: Always pass notifications when child class becomes empty Certain classful qdiscs may invoke their classes'...
Medium - CVE-2025-6997 - The ThemeREX Addons plugin for WordPress is...
The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.35.1.1 due to insufficient input sanitization and...
Critical - CVE-2012-10019 - The Front End Editor plugin for WordPress is...
The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it possible for...
High - CVE-2015-10133 - The Subscribe to Comments for WordPress is...
The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the Path to header value. This allows authenticated attackers, with...
High - CVE-2015-10134 - The Simple Backup plugin for WordPress is...
The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability...
Critical - CVE-2015-10135 - The WPshop 2 – E-Commerce plugin for WordPress...
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it...
High - CVE-2015-10136 - The GI-Media Library plugin for WordPress is...
The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read the...
Critical - CVE-2016-15043 - The WP Mobile Detector plugin for WordPress is...
The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it...