In Rich Shortcodes for Google Reviews plugin for WordPress versions up to and including 6.8 a high severity vulnerability CVE-2025-12499 was identified. This vulnerability occurs due to insufficient input sanitization and output escaping of Google Review contents, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses the injected page. Note that this vulnerability was partially patched in version 6.6.2. To address this issue, users should upgrade the plugin to version 6.8.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12499.
Read more CMSIn Easy Jump Links Menus plugin for WordPress versions up to and including 1.0.0 a medium severity vulnerability CVE-2025-13860 was identified. This vulnerability stems from insufficient input sanitization and output escaping of the h_tags parameter, allowing authenticated attackers with Contributor-level access and above to perform Stored Cross-Site Scripting (XSS). Successful exploitation enables injection of arbitrary web scripts that execute whenever a user accesses an infected page. To address this issue, users should upgrade the plugin to version 1.0.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13860.
Read more CMSIn Feedback Modal for Website plugin for WordPress versions up to and including 1.0.1 a medium severity vulnerability CVE-2025-13528 was identified. This vulnerability stems from a missing capability check on the handle_export function, allowing unauthenticated attackers to export all feedback data in CSV or JSON format via the export_data parameter. This can lead to unauthorized disclosure of sensitive user feedback information. To address this issue, users should upgrade the plugin to version 1.0.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13528
Read more CMSIn CRM Memberships plugin for WordPress versions up to and including 2.5 a critical severity vulnerability CVE-2025-13313 was identified. This vulnerability is caused by missing authorization and authentication checks on the ntzcrm_changepassword AJAX action, allowing unauthenticated attackers to reset arbitrary user passwords and gain unauthorized access to user accounts if they can obtain or enumerate a target user’s email address. Additionally, the plugin exposes the ntzcrm_get_users endpoint without authentication, enabling attackers to enumerate subscriber email addresses, which facilitates exploitation of the password reset vulnerability. To address this issue, users should upgrade the plugin to version 2.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13313.
Read more CMSIn Quantic Social Image Hover plugin for WordPress versions up to and including 1.0.8 a medium severity vulnerability CVE-2025-13360 was identified. This vulnerability is due to missing nonce validation on the settings update functionality, which allows unauthenticated attackers to update the plugin’s settings and inject malicious web scripts via a forged request if they can trick a site administrator into performing an action such as clicking on a link. To address this issue, users should upgrade the plugin to version 1.0.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13360.
Read more CMSIn SureMail – SMTP and Email Logs plugin for WordPress versions up to and including 1.9.0 a high severity vulnerability CVE-2025-13516 was detected. This vulnerability is due to unrestricted upload of files with dangerous types via the save_file() function, which saves email attachments to a web-accessible directory without proper validation. Although the plugin attempts to prevent PHP execution using an Apache .htaccess file, this protection is ineffective on nginx, IIS, Lighttpd, or misconfigured Apache servers. This flaw allows unauthenticated attackers to upload malicious PHP files and execute arbitrary code by accessing the files via predictable filenames. To address this issue, users should upgrade the plugin to version 1.9.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13516.
Read more CMSIn HUSKY – Products Filter Professional for WooCommerce plugin for WordPress versions up to and including 1.3.7.2 a medium severity vulnerability CVE-2025-13109 was detected. This vulnerability allows authenticated attackers with subscriber-level access and above to exploit missing validation in the woof_add_query and woof_remove_query functions. Successful exploitation enables attackers to insert or remove arbitrary saved search queries in any user’s profile, including administrators, leading to unauthorized modification of user data. To address this issue, users should upgrade the plugin to version 1.3.8 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13109.
Read more CMSIn Mautic versions 4.0 through 4.4.17, 5.0 through 5.2.8, and 6.0 through 6.0.6 a low critical vulnerability CVE-2025-13828 was detected. This vulnerability allows a non-privileged user without access to the Marketplace to install and uninstall arbitrary composer packages, even when the “enable composer based update” setting is disabled. This can lead to malicious code installation, enabling privilege escalation on the platform. To address this issue, users should upgrade Mautic to versions 4.4.18, 5.2.9, 6.0.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13828.
Read more Marketing AutomationIn Mautic versions 4.0 through 4.4.17, 5.0 through 5.2.8, and 6.0 through 6.0.6 a high severity vulnerability CVE-2025-13827 was detected. This vulnerability allows unauthenticated attackers to upload arbitrary files via the GrapesJS Builder due to lack of file type restrictions. If the media folder is not properly restricted from executing files, this can lead to remote code execution. To address this issue, users should upgrade Mautic to versions 4.4.18, 5.2.9, 6.0.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13827.
Read more Marketing Automation