CVE-2025-1309 – UiPress Lite WordPress Privilege Escalation Vulnerability

CVE ID : CVE-2025-1309 Published : March 7, 2025, 8:15 a.m. | 36 minutes ago Description : The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the uip_save_form_as_option() function in all […]

CVE-2025-0863 – Flexmls IDX Plugin Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-0863 Published : March 7, 2025, 8:15 a.m. | 36 minutes ago Description : The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘idx_frame’ shortcode in all versions up to, and including, 3.14.27 due to insufficient input sanitization and output escaping on user supplied attributes. This […]

CVE-2024-12837 – Oracle VirtualBox GPU Heap Corruption

The following table lists the changes that have been made to the CVE-2024-12837 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 367425dc-4d06-4041-9650-c2dc6aaa27ce Mar. 07, 2025 Action […]

CVE-2024-13906 – BestWebSoft Gallery PHP Object Injection Vulnerability

CVE ID : CVE-2024-13906 Published : March 7, 2025, 8:15 a.m. | 36 minutes ago Description : The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.7.3 via deserialization of untrusted input in the ‘import_gallery_from_csv’ function. This […]

CVE-2024-12576 – Adobe Flash Player GPU Crash

The following table lists the changes that have been made to the CVE-2024-12576 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 367425dc-4d06-4041-9650-c2dc6aaa27ce Mar. 07, 2025 Action […]

CVE-2024-13655 – “Flex Mag WordPress Theme Unauthenticated Option Deletion Vulnerability”

The following table lists the changes that have been made to the CVE-2024-13655 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 07, 2025 Action […]

CVE-2025-1475 – WordPress WPCOM Member Authentication Bypass Vulnerability

The following table lists the changes that have been made to the CVE-2025-1475 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 07, 2025 Action […]

CVE-2024-13320 – WooCommerce Multi Currency – Currency Switcher SQL Injection

The following table lists the changes that have been made to the CVE-2024-13320 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 07, 2025 Action […]

CVE-2024-12809 – WordPress Wishlist Stored Cross-Site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2024-12809 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 07, 2025 Action […]

CVE-2025-27796 – GraphicsMagick Palette Buffer Allocation Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2025-27796 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 07, 2025 Action […]