In TablePress plugin for WordPress versions up to and including 3.1.2 a medium severity vulnerability CVE-2025-5096 was detected. This DOM-based stored XSS vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the data-caption, data-s-content-padding, data-s-title and data-footerattributes. To address this issue, users should upgrade TablePress plugin to versions 3.1.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5096.
Read more CMSIn 4stats plugin for WordPress versions up to and including 2.0.9 a medium severity vulnerability CVE-2025-3869 was detected. This Cross-Site Request Forgery (CSRF) vulnerability, caused by missing or incorrect nonce validation on the stats/stats.php page, allows unauthenticated attackers to update settings and inject malicious web scripts via a forged request if they can trick a site administrator into performing an action such as clicking a link. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3869.
Read more CMSIn Exclusive Addons for Elementor plugin for WordPress versions up to and including 2.7.9.1 a medium severity vulnerability CVE-2025-4783 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the Countdown Timer Widget’s HTML attributes, which execute when a user accesses an affected page. To address this issue, users should upgrade Exclusive Addons for Elementor plugin to versions 2.7.9.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4783.
Read more CMSIn ClipArt plugin for WordPress versions through 0.2 a high severity vulnerability CVE-2024-12726 was detected. This vulnerability allows attackers to perform Reflected Cross-Site Scripting (XSS) attacks, which could be exploited against high privilege users such as administrators. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12726.
Read more CMSIn Hot Random Image plugin for WordPress versions up to and including 1.9.2 a medium severity vulnerability CVE-2025-4419 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to exploit a path traversal flaw via the ‘path’ parameter to access arbitrary images with allowed extensions outside the intended directory. To address this issue, users should upgrade Hot Random Image plugin to versions 1.9.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4419.
Read more CMSIn Hot Random Image plugin for WordPress versions up to and including 1.9.2 a medium severity vulnerability CVE-2025-4405 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via the ‘link’ parameter due to insufficient input sanitization and output escaping. To address this issue, users should upgrade Hot Random Image plugin to versions 1.9.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4405.
Read more CMSIn MapSVG plugin for WordPress versions up to and including 8.6.4 a medium severity vulnerability CVE-2024-9544 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to upload malicious SVG files that inject arbitrary web scripts, which execute whenever a user accesses the file. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9544.
Read more CMSIn WooCommerce plugin for WordPress versions 9.3.2 and prior, 9.4 up to 9.4.2, 9.4.2 and prior a medium severity vulnerability CVE-2025-5062 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts via the ‘customize-store’ page due to insufficient sanitization and escaping of PostMessage data. To address this issue, users should upgrade WooCommerce plugin to versions 9.3.4 or 9.4.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5062.
Read more CMSIn Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress versions before 8.4.0 a medium severity vulnerability CVE-2025-4133 was detected. This vulnerability allows users with the Contributor role to perform Cross-Site Scripting (XSS) attacks by injecting malicious scripts into post titles, which are not properly escaped when displayed in the dashboard. To address this issue, users should upgrade Blog2Social: Social Media Auto Post & Scheduler plugin to versions 8.4.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4133.
Read more CMS