CVE-2025-8360 – LA-Studio Element Kit for Elementor <= 1.5.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

CVE ID : CVE-2025-8360 Published : Sept. 6, 2025, 2:24 a.m. | 15 minutes ago Description : The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin’s widgets in all versions up to, and including, 1.5.5.1 due to insufficient input sanitization and output escaping on user […]

CVE-2025-7368 – Rehub <= 19.9.7 – Unauthenticated Password Protected Post Disclosure

CVE ID : CVE-2025-7368 Published : Sept. 6, 2025, 2:15 a.m. | 24 minutes ago Description : The REHub – Price Comparison, Multi Vendor Marketplace WordPress Theme theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 19.9.7 via the ‘ajax_action_re_getfullcontent’ function due to insufficient restrictions on which posts can be […]

CVE-2025-6067 – Easy Social Feed – Social Photos Gallery – Post Feed – Like Box <= 6.6.7 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

CVE ID : CVE-2025-6067 Published : Sept. 6, 2025, 2:15 a.m. | 24 minutes ago Description : The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` and `data-linktext` parameters in all versions up to, and including, 6.6.7 due to […]

CVE-2025-58439 – ERP: Possibility of SQL injection due to missing validation

The following table lists the changes that have been made to the CVE-2025-58439 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 06, 2025 Action […]

CVE-2025-58375 – Apache Struts Remote Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2025-58375 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Sep. 06, 2025 Action Type […]

Two New High-Severity Flaws in FreePBX Puts Admins and APIs at Risk

Two New High-Severity Flaws in FreePBX Puts Admins and APIs at Risk The FreePBX project has issued an important security advisory addressing two vulnerabilities that pose significant risks to administrators and API-integrated systems. The flaws—CVE-2025-55209 (CVSS 7. … Read more Published Date: Sep 06, 2025 (8 hours, 26 minutes ago) Vulnerabilities has been mentioned in this article. […]