CVE-2025-9346 – Booking Calendar for WordPress Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-9346 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
CVE-2025-9345 – Managefy Plugin Path Traversal Vulnerability
The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.8 via the ajax_downloadfile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory.
CVE-2025-8603 – Unlimited Elements For Elementor WordPress Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-8603 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
CVE-2025-0951 – LiquidThemes WordPress Theme and Plugin Unauthorized Access Vulnerability
The following table lists the changes that have been made to the CVE-2025-0951 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
CVE-2024-9648 – WordPress WP ULike Pro File Upload Vulnerability
The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the WP_Ulike_Pro_File_Uploader class in all versions up to, and including, 1.9.3. This makes it possible for unauthenticated attackers to upload limited arbitrary files like .php2, .php6, .php7, .phps, .pht, .phtm, .pgif, .shtml, .phar, .inc, .hphp, […]
CVE-2025-9352 – Pronamic Google Maps for WordPress Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-9352 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
CVE-2025-9344 – UsersWP WordPress Stored Cross-Site Scripting Vulnerability
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘uwp_profile’ and ‘uwp_profile_header’ shortcodes in all versions up to, and including, 1.2.42 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it […]
CVE-2025-8897 – Beaver Builder WordPress Page Builder Reflected Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-8897 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
CVE-2025-57845 – Apache HTTP Server Remote Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2025-57845 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Aug. 28, 2025 Action Type […]
CVE-2025-7812 – Video Share VOD WordPress CSRF Vulnerability
The following table lists the changes that have been made to the CVE-2025-7812 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]