Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Get Started
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash
  • Business and Enterprise Solutions
  • CMS

CMS

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Selected category
    • Communication
      • Communication
    • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • Networking
      • Storage
      • Security
    • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    22 May 2025 Business and Enterprise Solutions
    WordPress: Stored XSS via ‘link’ Parameter in Hot Random Image Plugin

    In Hot Random Image plugin for WordPress versions up to and including 1.9.2 a medium severity vulnerability CVE-2025-4405 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via the ‘link’ parameter due to insufficient input sanitization and output escaping. To address this issue, users should upgrade Hot Random Image plugin to versions 1.9.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4405.

    Read more
    CMS
    22 May 2025 Business and Enterprise Solutions
    WordPress: Stored XSS via SVG Uploads in MapSVG Plugin

    In MapSVG plugin for WordPress versions up to and including 8.6.4 a medium severity vulnerability CVE-2024-9544 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to upload malicious SVG files that inject arbitrary web scripts, which execute whenever a user accesses the file. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9544.

    Read more
    CMS
    22 May 2025 Business and Enterprise Solutions
    WordPress: PostMessage-Based XSS via ‘customize-store’ Page in WooCommerce Plugin

    In WooCommerce plugin for WordPress versions 9.3.2 and prior, 9.4 up to 9.4.2, 9.4.2 and prior a medium severity vulnerability CVE-2025-5062 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts via the ‘customize-store’ page due to insufficient sanitization and escaping of PostMessage data. To address this issue, users should upgrade WooCommerce plugin to versions 9.3.4 or 9.4.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5062.

    Read more
    CMS
    22 May 2025 Business and Enterprise Solutions
    WordPress: Stored XSS via Unescaped Post Titles in Blog2Social Plugin

    In Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress versions before 8.4.0 a medium severity vulnerability CVE-2025-4133 was detected. This vulnerability allows users with the Contributor role to perform Cross-Site Scripting (XSS) attacks by injecting malicious scripts into post titles, which are not properly escaped when displayed in the dashboard. To address this issue, users should upgrade Blog2Social: Social Media Auto Post & Scheduler plugin to versions 8.4.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4133.

    Read more
    CMS
    21 May 2025 Business and Enterprise Solutions
    WordPress: Reflected XSS via Unsanitized Parameter in AffiliateImporterEb Plugin

    In AffiliateImporterEb plugin for WordPress versions through 1.0.6 a high severity vulnerability CVE-2024-12733 was detected. This vulnerability allows attackers to perform Reflected Cross-Site Scripting (XSS) attacks, which could be exploited against high privilege users such as administrators. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12733.

    Read more
    CMS
    20 May 2025 Business and Enterprise Solutions
    WordPress: Stored XSS via Unsanitized Settings in Ninja Forms Plugin

    In the Ninja Forms WordPress plugin versions prior to 3.10.1 a low severity vulnerability CVE-2025-2524 was detected. This vulnerability allows high privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (e.g., in a multisite setup), due to insufficient sanitization and escaping of plugin settings. To address this issue, users should upgrade the Ninja Forms WordPress plugin to version 3.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2524.

    Read more
    CMS
    20 May 2025 Business and Enterprise Solutions
    WordPress: Stored XSS via Countdown Block Options in Qi Blocks Plugin

    In the Qi Blocks WordPress plugin versions prior to 1.4 a medium severity vulnerability CVE-2025-1626 was detected. This vulnerability allows authenticated users with Contributor-level access and above to perform Stored Cross-Site Scripting (XSS) attacks due to insufficient validation and escaping of Countdown block options before rendering them in a page or post. To address this issue, users should upgrade the Qi Blocks WordPress plugin to version 1.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1626.

    Read more
    CMS
    20 May 2025 Business and Enterprise Solutions
    WordPress: Privilege Escalation via Password Reset in Motors Theme

    In the Motors theme for WordPress versions up to and including 5.6.67 a critical severity vulnerability CVE-2025-4322 was detected. This vulnerability allows unauthenticated attackers to escalate privileges by taking over user accounts, including administrator accounts, through improper identity validation during password updates. To address this issue, users should upgrade the Motors theme to versions 5.6.68 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4322.

    Read more
    CMS
    19 May 2025 Business and Enterprise Solutions
    WordPress: Sensitive Information Exposure via Insecure Uploads Directory in Wise Chat Plugin

    In Wise Chat plugin for WordPress versions up to and including 3.3.3 a high severity vulnerability CVE-2024-13613 was detected. This vulnerability allows unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory, potentially exposing file attachments from chat messages. To address this issue, users should upgrade Wise Chat plugin to versions 3.3.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13613.

    Read more
    CMS
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base
    © HOSSTED 2025 All rights reserved
    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy