CVE-2025-2616 – Yangyouwang CRUD Simplified Backend Management System Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-2616 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 22, 2025 Action […]

CVE-2024-13666 – Fluent Forms IP Address Spoofing Vulnerability

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated […]

CVE-2025-2482 – WordPress Gesture-based Captcha Reflected Cross-Site Scripting

CVE ID : CVE-2025-2482 Published : March 22, 2025, 7:15 a.m. | 2 hours, 3 minutes ago Description : The Gotcha | Gesture-based Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘menu’ parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible […]

CVE-2025-2479 – WordPress Easy Custom Admin Bar Reflected Cross-Site Scripting

CVE ID : CVE-2025-2479 Published : March 22, 2025, 7:15 a.m. | 2 hours, 3 minutes ago Description : The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible […]

CVE-2025-2478 – WordPress Code Clone SQL Injection Vulnerability

CVE ID : CVE-2025-2478 Published : March 22, 2025, 7:15 a.m. | 2 hours, 3 minutes ago Description : The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the ‘snippetId’ parameter in all versions up to, and including, 0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation […]

CVE-2025-2477 – CryoKey WordPress Reflected Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-2477 Published : March 22, 2025, 7:15 a.m. | 2 hours, 3 minutes ago Description : The CryoKey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ckemail’ parameter in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers […]

CVE-2025-2303 – Block Logic – WordPress Full Gutenberg Block Display Control Remote Code Execution

The following table lists the changes that have been made to the CVE-2025-2303 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 22, 2025 Action […]

CVE-2025-1311 – WooCommerce Multivendor Marketplace – SQL Injection

CVE ID : CVE-2025-1311 Published : March 22, 2025, 7:15 a.m. | 2 hours, 3 minutes ago Description : The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in the update_delivery_status() function in all versions up to, and including, 1.6.2 due to insufficient escaping on the user […]

CVE-2025-0807 – WordPress CITS Support Use Custom Fonts CSRF

CVE ID : CVE-2025-0807 Published : March 22, 2025, 7:15 a.m. | 2 hours, 3 minutes ago Description : The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce […]