CVE-2015-10133 – WordPress Subscribe to Comments Local File Inclusion Vulnerability
CVE ID : CVE-2015-10133 Published : July 19, 2025, 10:15 a.m. | 1 hour, 24 minutes ago Description : The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the Path to header value. This allows authenticated attackers, with administrative privileges and above, to include and execute […]
CVE-2012-10019 – WordPress Front End Editor Arbitrary File Upload Vulnerability
CVE ID : CVE-2012-10019 Published : July 19, 2025, 10:15 a.m. | 1 hour, 24 minutes ago Description : The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it possible for unauthenticated attackers to upload arbitrary files […]
New CrushFTP 0-Day Vulnerability Exploited in the Wild to Gain Access to Servers
New CrushFTP 0-Day Vulnerability Exploited in the Wild to Gain Access to Servers A critical zero-day flaw in the CrushFTP managed file-transfer platform was confirmed after vendor and threat-intelligence sources confirmed active exploitation beginning on 18 July 2025 at 09:00 CST. … Read more Published Date: Jul 19, 2025 (3 hours, 47 minutes ago) Vulnerabilities has been […]
CVE-2025-6997 – “ThemeREX Addons WordPress Stored Cross-Site Scripting”
The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.35.1.1 due to insufficient input sanitization and output escaping. The plugin’s SVG rendering routine calls the trx_addons_get_svg_from_file() function on an unvalidated ‘svg’ parameter supplied via the shortcode or Elementor widget settings, then […]
CVE-2025-38350 – Linux Kernel HFSC Netem Blackhole Use-After-Free Vulnerability
The following table lists the changes that have been made to the CVE-2025-38350 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Jul. 19, 2025 Action […]
CVE-2025-6721 – WordPress Vchasno Kasa Plugin Unauthenticated Data Access Vulnerability
CVE ID : CVE-2025-6721 Published : July 19, 2025, 6:15 a.m. | 1 hour, 1 minute ago Description : The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mrkv_vchasno_kasa_wc_do_metabox_action() function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers […]
CVE-2025-6720 – Vchasno Kasa Plugin WordPress Information Disclosure Vulnerability
CVE ID : CVE-2025-6720 Published : July 19, 2025, 6:15 a.m. | 1 hour, 1 minute ago Description : The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers […]
CVE-2025-29757 – Growatt Cloud Service Authorization Bypass Vulnerability
The following table lists the changes that have been made to the CVE-2025-29757 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 19, 2025 Action […]
CVE-2025-7696 – Pipedrive WordPress Plugin PHP Object Injection Vulnerability
The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.3 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a […]
CVE-2025-7697 – Google Sheets Integration for WordPress PHP Object Injection Vulnerability
The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of […]