Critical - CVE-2025-0177 - The Javo Core plugin for WordPress is...
The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts...
Medium - CVE-2025-1287 - The The Plus Addons for Elementor – Elementor...
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown, Syntax...
High - CVE-2024-13359 - The Product Input Fields for WooCommerce plugin...
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta()...
Medium - CVE-2025-1322 - The WP-Recall – Registration, Profile, Commerce...
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the 'feed' shortcode...
High - CVE-2025-1323 - The WP-Recall – Registration, Profile, Commerce...
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due...
Medium - CVE-2025-1324 - The WP-Recall – Registration, Profile, Commerce...
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'public-form' shortcode in all versions up...
Medium - CVE-2025-1325 - The WP-Recall – Registration, Profile, Commerce...
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the 'rcl_preview_post' AJAX...
Medium - CVE-2025-1783 - The Gallery Styles plugin for WordPress is...
The Gallery Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery Block in all versions up to, and including, 1.3.4 due to insufficient input sanitization and...
High - CVE-2024-11640 - The VikRentCar Car Rental Management System...
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce...
Medium - CVE-2024-13649 - The 140+ Widgets | Xpro Addons For Elementor –...
The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.4.6.7 due to...