CVE-2025-3832 – “FuseDesk WordPress Stored Cross-Site Scripting Vulnerability”
CVE ID : CVE-2025-3832 Published : April 24, 2025, 9:15 a.m. | 1 hour, 51 minutes ago Description : The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, […]
CVE-2025-3793 – Buddypress WordPress Force Password Change Plugin Authentication Bypass
CVE ID : CVE-2025-3793 Published : April 24, 2025, 9:15 a.m. | 1 hour, 51 minutes ago Description : The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user’s identity prior to updating their password through the ‘bp_force_password_ajax’ function in all versions up to, […]
CVE-2025-3776 – WordPress TargetSMS Plugin Remote Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2025-3776 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]
CVE-2025-3607 – WordPress Frontend Login and Registration Blocks Privilege Escalation Vulnerability
The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.7. This is due to the plugin not properly validating a user’s identity prior to updating a password. This makes it possible for authenticated attackers, with Subscriber-level access and above, to […]
CVE-2025-3604 – Flynax Bridge WordPress Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-3604 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]
CVE-2025-3300 – “WordPress WPMasterToolKit Directory Traversal Vulnerability”
CVE ID : CVE-2025-3300 Published : April 24, 2025, 9:15 a.m. | 1 hour, 51 minutes ago Description : The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to read […]
CVE-2025-3280 – ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes SQL Injection
CVE ID : CVE-2025-3280 Published : April 24, 2025, 9:15 a.m. | 1 hour, 51 minutes ago Description : The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection via the ‘attribute_value_filter’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied […]
CVE-2025-3603 – Flynax Bridge for WordPress Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-3603 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]
CVE-2025-3101 – WordPress Configurator Theme Core Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-3101 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]
CVE-2025-3065 – Apache Database Toolset Remote File Deletion Vulnerability
The following table lists the changes that have been made to the CVE-2025-3065 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]