CVE-2025-3784 – Information Disclosure Vulnerability in GX Works2
The following table lists the changes that have been made to the CVE-2025-3784 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]
CVE-2025-12758 – Validator Package Unicode Filtering Vulnerability
The following table lists the changes that have been made to the CVE-2025-12758 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]
CVE-2025-13539 – FindAll Membership <= 1.0.4 – Authentication Bypass via Social Login
CVE ID : CVE-2025-13539 Published : Nov. 27, 2025, 4:36 a.m. | 43 minutes ago Description : The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.4. This is due to the plugin not properly logging in a user with the data that was previously verified through […]
CVE-2025-13540 – Tiare Membership <= 1.2 – Unauthenticated Privilege Escalation
CVE ID : CVE-2025-13540 Published : Nov. 27, 2025, 4:36 a.m. | 43 minutes ago Description : The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the ‘tiare_membership_init_rest_api_register’ function not restricting what user roles a user can register with. This makes it […]
CVE-2025-13680 – Tiger <= 101.2.1 – Authenticated (Subscriber+) Privilege Escalation
CVE ID : CVE-2025-13680 Published : Nov. 27, 2025, 4:36 a.m. | 43 minutes ago Description : The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the plugin allowing a user to update the user role through the $user->set_role() function. This makes it […]
CVE-2025-12151 – Simple Folio <= 1.1.0 – Authenticated (Subscriber+) Stored Cross-Site Scripting
CVE ID : CVE-2025-12151 Published : Nov. 27, 2025, 4:36 a.m. | 43 minutes ago Description : The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘portfolio_name’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, […]
CVE-2025-13675 – Tiger <= 101.2.1 – Unauthenticated Privilege Escalation
CVE ID : CVE-2025-13675 Published : Nov. 27, 2025, 4:36 a.m. | 43 minutes ago Description : The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the ‘paypal-submit.php’ file not restricting what user roles a user can register with. This makes it possible […]
CVE-2025-7820 – SKT PayPal for WooCommerce <= 1.4 – Unauthenticated Payment Bypass
CVE ID : CVE-2025-7820 Published : Nov. 27, 2025, 4:36 a.m. | 43 minutes ago Description : The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 1.4. This is due to the plugin only enforcing client side controls instead of server-side controls when processing payments. […]
CVE-2025-13538 – FindAll Listing <= 1.0.5 – Unauthenticated Privilege Escalation
CVE ID : CVE-2025-13538 Published : Nov. 27, 2025, 4:36 a.m. | 43 minutes ago Description : The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the ‘findall_listing_user_registration_additional_params’ function not restricting what user roles a user can register with. This makes it […]
Security Alert: Apache SkyWalking Stored XSS Vulnerability (CVE-2025-54057)
Security Alert: Apache SkyWalking Stored XSS Vulnerability (CVE-2025-54057) Apache SkyWalking, the widely adopted open-source Application Performance Monitoring (APM) system used for distributed systems in Cloud Native architectures, has released a critical security update. T … Read more Published Date: Nov 27, 2025 (1 hour, 50 minutes ago) Vulnerabilities has been mentioned in this article.