In WP01 plugin for WordPress versions up to and including 2.6.2 a medium severity vulnerability CVE-2025-2267 was detected. This vulnerability allows authenticated attackers with Subscriber-level access and above to download arbitrary files from the server due to a missing capability check and insufficient restrictions on the make_archive() function. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2267.
Read more CMSIn Pixelstats plugin for WordPress versions up to and including 0.8.2 a medium severity vulnerability CVE-2025-2164 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts via the ‘post_id’ and ‘sortby’ parameters due to insufficient input sanitization and output escaping, which execute when a user is tricked into performing an action like clicking on a link. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2164.
In Tripetto plugin for WordPress versions up to and including 8.0.9 a medium severity vulnerability CVE-2025-1530 was detected. This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) due to missing nonce validation. This makes it possible for unauthenticated attackers to delete arbitrary results by tricking a site administrator into performing an action such as clicking on a link. To address this issue, users should upgrade Tripetto plugin to versions 8.0.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1530.
Read more CMSIn SoundRise Music plugin for WordPress versions up to and including 1.6.11 a high vulnerability CVE-2025-2103 was detected. This vulnerability allows authenticated attackers with subscriber-level access and above to modify WordPress site options due to a missing capability check in the theironMusic_ajax() function, enabling them to change the default registration role to administrator and gain administrative access. To address this issue, users should upgrade SoundRise Music plugin to versions 1.7.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2103.
Read more CMSIn the Omnipress plugin for WordPress versions 1.5.4 and prior a medium severity vulnerability CVE-2024-13407 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to extract data from password-protected, private, or draft posts via the megamenu block. To address this issue, users should upgrade Omnipress plugin to the versions 1.5.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13407.
Read more CMSIn AnalyticsWP plugin for WordPress versions 2.0.0 and prior a high severity vulnerability CVE-2024-13321 was detected. This vulnerability allows unauthenticated attackers to perform SQL injection via the ‘custom_sql’ parameter due to insufficient authorization checks in the handle_get_stats() function, enabling them to append additional SQL queries and extract sensitive information from the database. To address this issue, users should upgrade AnalyticsWP plugin to versions 2.1.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13321.
Read more CMSIn Joomla versions 4.0.0 up to and including 4.4.11, 5.1.0 up to and including 5.2.4 a high severity vulnerability CVE-2025-22213 was detected in the Media Manager. This vulnerability allows users with “edit” privileges to change file extensions to arbitrary values, including .php and other potentially executable extensions, which could lead to unauthorized code execution. To address this issue, users should upgrade Joomla to versions 4.4.12 or 5.2.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-22213.
Read more CMSIn Umbraco versions prior to 15.2.3 and prior to 14.3.3 a medium severity vulnerability CVE-2025-27601 was detected. This vulnerability allows low-privilege, authenticated users to create and update data type information, which should be restricted to users with access to the settings section. To address this issue, users should upgrade Umbraco to versions 15.2.3 or 14.3.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27601.
Read more CMSIn Umbraco versions prior to 10.8.9 and prior to 13.7.1 a medium severity vulnerability CVE-2025-27602 was detected. This vulnerability allows authenticated backoffice users to retrieve or delete content and media from restricted folders by manipulating backoffice API URLs. To address this issue, users should upgrade Umbraco to versions 10.8.9 and 13.7.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27602.
Read more CMS