CVE/PSC | Application | Date | Affected versions | Description |
---|---|---|---|---|
Actual on: Jul 12, 2025, 08:07:56 | ||||
vulnerable
|
Jul 12, 2025, 13:07:35 |
Min -
Max 1.0.0
|
Media Folder [media-folder] <= 1.0.0 (unfixed) CVE-2025-52786 | |
vulnerable
|
Jul 12, 2025, 12:07:37 |
Min -
Max 1.8.1
|
SMu Manual DoFollow [manuall-dofollow] <= 1.8.1 (unfixed) CVE-2025-49031 | |
Premium SEO Pack – WP SEO Plugin
vulnerable
|
Jul 12, 2025, 12:07:35 |
Min -
Max 3.3.2
|
Premium SEO Pack – WP SEO Plugin [premium-seo-pack] <= 3.3.2 (unfixed) CVE-2025-31044 | |
vulnerable
|
Jul 12, 2025, 12:07:33 |
Min -
Max 1.40
|
PW WooCommerce On Sale! [pw-woocommerce-on-sale] < 1.40 CVE-2025-49888 | |
vulnerable
|
Jul 09, 2025, 22:07:15 |
Min -
Max 2.2.0
|
Missing Authorization vulnerability in Melapress Melapress File Monitor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Melapress File Monitor: from n/a before 2.2.0. | |
vulnerable
|
Jul 09, 2025, 15:07:33 |
Min -
Max 1.0.16
|
The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be up... | |
Lightbox & Modal Popup WordPress Plugin – FooBox
vulnerable
|
Jul 09, 2025, 04:07:30 |
Min -
Max 2.7.35
|
The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alternative texts in all versions up to, and including, 2.7.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
vulnerable
|
Jul 09, 2025, 01:07:32 |
Min -
Max 6.1.20
|
The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
vulnerable
|
Jul 09, 2025, 00:07:42 |
Min -
Max 2.8.5
|
The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
Guest Support – Complete customer support ticket system for WordPress
vulnerable
|
Jul 08, 2025, 18:07:45 |
Min -
Max 1.2.3
|
The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteMassTickets' function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to delete arbitrary support tickets. |