CVE/PSC | Application | Date | Affected versions | Description |
---|---|---|---|---|
Actual on: Jun 14, 2025, 03:06:57 | ||||
Sunshine Photo Cart: Free Client Galleries for Photographers
vulnerable
|
Jun 13, 2025, 10:06:32 |
Min -
Max 3.4.12
|
The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.11. This is due to the plugin not properly validating a user-supplied key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's passwords through the password reset functionality, including administrators, and leverage that to reset the user's password ... | |
vulnerable
|
Jun 13, 2025, 02:06:02 |
Min -
Max 1.4.1
|
The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
vulnerable
|
Jun 12, 2025, 05:06:36 |
Min -
Max 2.1.17
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes allows Reflected XSS. This issue affects Arconix Shortcodes: from n/a through 2.1.16. | |
Slim SEO – Fast & Automated WordPress SEO Plugin
vulnerable
|
Jun 12, 2025, 04:06:32 |
Min -
Max 4.5.4
|
The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
AutomatorWP – The #1 automator plugin for no-code automation in WordPress
vulnerable
|
Jun 11, 2025, 14:06:34 |
Min -
Max 5.2.2
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP allows Blind SQL Injection. This issue affects AutomatorWP: from n/a through 5.2.1.3. | |
vulnerable
|
Jun 11, 2025, 07:06:45 |
Min -
Max 7.7.1
|
The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ parameter in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
vulnerable
|
Jun 10, 2025, 07:06:49 |
Min -
Max 1.6.3
|
The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fip_save_attach_featured function in all versions up to, and including, 1.6.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update featured image of any post. | |
Products per Page for WooCommerce
vulnerable
|
Jun 10, 2025, 03:06:35 |
Min -
Max 2.5.0
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Custom Checkout Fields for WooCommerce allows Stored XSS. This issue affects Custom Checkout Fields for WooCommerce: from n/a through 1.8.3. | |
Min Max Default Quantity for WooCommerce
vulnerable
|
Jun 09, 2025, 05:06:38 |
Min -
Max 5.0.4
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Custom Checkout Fields for WooCommerce allows Stored XSS. This issue affects Custom Checkout Fields for WooCommerce: from n/a through 1.8.3. | |
vulnerable
|
Jun 06, 2025, 19:06:22 |
Min -
Max 6.2.8
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Innovations The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 6.2.7. |