CVE-2025-2228 - Elementor Responsive Addons WordPress Sensitive Information Exposure
Published: Wed, 26 Mar 2025 13:15:36 +0000
CVE ID : CVE-2025-2228
Published : March 26, 2025, 1:15 p.m. | 31 minutes ago
Description : The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.8 the 'register_user' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including usernames and passwords of any users who register via the Edit Login | Registration Form widget, as long as that user opens the email notification for successful registration.
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2110 - WordPress WP Compress Unauthorized Access and Data Manipulation Vulnerability
Published: Wed, 26 Mar 2025 12:15:15 +0000
CVE ID : CVE-2025-2110
Published : March 26, 2025, 12:15 p.m. | 1 hour, 31 minutes ago
Description : The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its AJAX functions in all versions up to, and including, 6.30.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to compromise the site in various ways depending on the specific function exploited - for example, by retrieving sensitive settings and configuration details, or by altering and deleting them, thereby disclosing sensitive information, disrupting the plugin’s functionality, and potentially impacting overall site performance.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1913 - WooCommerce Product Import Export - PHP Object Injection Vulnerability
Published: Wed, 26 Mar 2025 12:15:15 +0000
CVE ID : CVE-2025-1913
Published : March 26, 2025, 12:15 p.m. | 1 hour, 31 minutes ago
Description : The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via deserialization of untrusted input from the 'form_data' parameter This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1912 - WooCommerce Product Import Export Plugin SSRF Vulnerability
Published: Wed, 26 Mar 2025 12:15:15 +0000
CVE ID : CVE-2025-1912
Published : March 26, 2025, 12:15 p.m. | 1 hour, 31 minutes ago
Description : The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the validate_file() Function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1911 - WooCommerce Product Import Export Arbitrary File Deletion Vulnerability
Published: Wed, 26 Mar 2025 12:15:15 +0000
CVE ID : CVE-2025-1911
Published : March 26, 2025, 12:15 p.m. | 1 hour, 31 minutes ago
Description : The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.5.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary log files on the server.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1769 - WooCommerce Product Import Export Directory Traversal Vulnerability
Published: Wed, 26 Mar 2025 12:15:15 +0000
CVE ID : CVE-2025-1769
Published : March 26, 2025, 12:15 p.m. | 1 hour, 31 minutes ago
Description : The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1312 - WordPress Blocks Plugin Stored Cross-Site Scripting Vulnerability
Published: Wed, 26 Mar 2025 12:15:14 +0000
CVE ID : CVE-2025-1312
Published : March 26, 2025, 12:15 p.m. | 1 hour, 31 minutes ago
Description : The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttonTextColor’ parameter in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-13889 - WordPress Importer PHP Object Injection Vulnerability
Published: Wed, 26 Mar 2025 12:15:14 +0000
CVE ID : CVE-2024-13889
Published : March 26, 2025, 12:15 p.m. | 1 hour, 31 minutes ago
Description : The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of untrusted input in the 'maybe_unserialize' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-13411 - Zapier for WordPress SSRF Vulnerability
Published: Wed, 26 Mar 2025 12:15:13 +0000
CVE ID : CVE-2024-13411
Published : March 26, 2025, 12:15 p.m. | 1 hour, 31 minutes ago
Description : The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5.1 via the updated_user() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2596 - Checkmk GmbH Checkmk Session Logout Overwrite Vulnerability
Published: Wed, 26 Mar 2025 11:15:39 +0000
CVE ID : CVE-2025-2596
Published : March 26, 2025, 11:15 a.m. | 2 hours, 30 minutes ago
Description : Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27552 - DBIx::Class::EncodedColumn Cryptographic Password Hashing Weakness
Published: Wed, 26 Mar 2025 11:15:39 +0000
CVE ID : CVE-2025-27552
Published : March 26, 2025, 11:15 a.m. | 2 hours, 30 minutes ago
Description : DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes.
This vulnerability is associated with program files Crypt/Eksblowfish/Bcrypt.pm.
This issue affects DBIx::Class::EncodedColumn until 0.00032.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27551 - DBIx::Class::EncodedColumn Cryptographically Insecure Password Hashing
Published: Wed, 26 Mar 2025 11:15:38 +0000
CVE ID : CVE-2025-27551
Published : March 26, 2025, 11:15 a.m. | 2 hours, 30 minutes ago
Description : DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes.
This vulnerability is associated with program files lib/DBIx/Class/EncodedColumn/Digest.pm.
This issue affects DBIx::Class::EncodedColumn until 0.00032.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1542 - OXARI ServiceDesk Privilege Escalation Vulnerability
Published: Wed, 26 Mar 2025 11:15:38 +0000
CVE ID : CVE-2025-1542
Published : March 26, 2025, 11:15 a.m. | 2 hours, 30 minutes ago
Description : Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before 2.0.324.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1703 - WordPress Ultimate Blocks Stored Cross-Site Scripting Vulnerability
Published: Wed, 26 Mar 2025 10:15:15 +0000
CVE ID : CVE-2025-1703
Published : March 26, 2025, 10:15 a.m. | 3 hours, 31 minutes ago
Description : The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1440 - WordPress Advanced iFrame Plugin Unauthenticated Option Excessive Creation
Published: Wed, 26 Mar 2025 10:15:15 +0000
CVE ID : CVE-2025-1440
Published : March 26, 2025, 10:15 a.m. | 3 hours, 31 minutes ago
Description : The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option with an excessive amount of unvalidated data.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1439 - WordPress Advanced iFrame Stored Cross-Site Scripting Vulnerability
Published: Wed, 26 Mar 2025 10:15:15 +0000
CVE ID : CVE-2025-1439
Published : March 26, 2025, 10:15 a.m. | 3 hours, 31 minutes ago
Description : The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to insufficient input sanitization and output escaping on user supplied attributes through the 'src' attribute when the src supplied returns a header with an injected value . This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1437 - WordPress Advanced iFrame Stored Cross-Site Scripting Vulnerability
Published: Wed, 26 Mar 2025 10:15:14 +0000
CVE ID : CVE-2025-1437
Published : March 26, 2025, 10:15 a.m. | 3 hours, 31 minutes ago
Description : The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1310 - "WordPress Jobs Plugin Directory Traversal Vulnerability"
Published: Wed, 26 Mar 2025 10:15:14 +0000
CVE ID : CVE-2025-1310
Published : March 26, 2025, 10:15 a.m. | 3 hours, 31 minutes ago
Description : The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.7.11 via the 'job_postings_get_file' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2257 - BoldGrid WordPress Backup Plugin Remote Code Execution
Published: Wed, 26 Mar 2025 09:15:16 +0000
CVE ID : CVE-2025-2257
Published : March 26, 2025, 9:15 a.m. | 4 hours, 31 minutes ago
Description : The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using the compression_level setting in proc_open() without any validation. This makes it possible for authenticated attackers, with administrator-level access and above, to execute code on the server.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2167 - WordPress Event Post Stored Cross-Site Scripting Vulnerability
Published: Wed, 26 Mar 2025 09:15:16 +0000
CVE ID : CVE-2025-2167
Published : March 26, 2025, 9:15 a.m. | 4 hours, 31 minutes ago
Description : The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcodes in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2009 - WordPress Newsletters Stored Cross-Site Scripting Vulnerability
Published: Wed, 26 Mar 2025 09:15:16 +0000
CVE ID : CVE-2025-2009
Published : March 26, 2025, 9:15 a.m. | 4 hours, 31 minutes ago
Description : The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logging functionality in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1514 - WooCommerce Active Products Tables Plugin Filter Injection Vulnerability
Published: Wed, 26 Mar 2025 09:15:15 +0000
CVE ID : CVE-2025-1514
Published : March 26, 2025, 9:15 a.m. | 4 hours, 31 minutes ago
Description : The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized filter calling due to insufficient restrictions on the get_smth() function in all versions up to, and including, 1.0.6.7. This makes it possible for unauthenticated attackers to call arbitrary WordPress filters with a single parameter.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-13801 - WordPress BWL Advanced FAQ Manager Unauthorized Data Modification and Denial of Service
Published: Wed, 26 Mar 2025 09:15:15 +0000
CVE ID : CVE-2024-13801
Published : March 26, 2025, 9:15 a.m. | 4 hours, 31 minutes ago
Description : The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'baf_set_notice_status' AJAX action in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to '1' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to set some values to true such as registration.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-13702 - vcita WordPress Stored Cross-Site Scripting
Published: Wed, 26 Mar 2025 09:15:14 +0000
CVE ID : CVE-2024-13702
Published : March 26, 2025, 9:15 a.m. | 4 hours, 31 minutes ago
Description : The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler' and 'vCitaSchedulingCalendar' shortcodes in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-30155 - HCL SX CSRF Token Tampering
Published: Wed, 26 Mar 2025 08:15:12 +0000
CVE ID : CVE-2024-30155
Published : March 26, 2025, 8:15 a.m. | 5 hours, 31 minutes ago
Description : HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...