In AffiliateImporterEb plugin for WordPress versions through 1.0.6 a high severity vulnerability CVE-2024-12733 was detected. This vulnerability allows attackers to perform Reflected Cross-Site Scripting (XSS) attacks, which could be exploited against high privilege users such as administrators. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12733.
Read more CMSIn the Qi Blocks WordPress plugin versions prior to 1.4 a medium severity vulnerability CVE-2025-1626 was detected. This vulnerability allows authenticated users with Contributor-level access and above to perform Stored Cross-Site Scripting (XSS) attacks due to insufficient validation and escaping of Countdown block options before rendering them in a page or post. To address this issue, users should upgrade the Qi Blocks WordPress plugin to version 1.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1626.
Read more CMSIn the Motors theme for WordPress versions up to and including 5.6.67 a critical severity vulnerability CVE-2025-4322 was detected. This vulnerability allows unauthenticated attackers to escalate privileges by taking over user accounts, including administrator accounts, through improper identity validation during password updates. To address this issue, users should upgrade the Motors theme to versions 5.6.68 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4322.
Read more CMSIn the Ninja Forms WordPress plugin versions prior to 3.10.1 a low severity vulnerability CVE-2025-2524 was detected. This vulnerability allows high privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (e.g., in a multisite setup), due to insufficient sanitization and escaping of plugin settings. To address this issue, users should upgrade the Ninja Forms WordPress plugin to version 3.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2524.
Read more CMSIn Wise Chat plugin for WordPress versions up to and including 3.3.3 a high severity vulnerability CVE-2024-13613 was detected. This vulnerability allows unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory, potentially exposing file attachments from chat messages. To address this issue, users should upgrade Wise Chat plugin to versions 3.3.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13613.
Read more CMSIn WP Booking Calendar plugin for WordPress versions up to and including 10.11.1 a medium severity vulnerability CVE-2025-4669 was detected. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts via the wpbc shortcode, which execute when a user accesses an injected page, due to insufficient input sanitization and output escaping. To address this issue, users should upgrade WP Booking Calendar plugin to versions 10.11.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4669.
Read more CMSIn Jupiter X Core plugin for WordPress versions up to and including 4.8.12 a medium severity vulnerability CVE-2025-3888 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via SVG file inclusion due to insufficient input sanitization and output escaping, leading to script execution when a user accesses the affected page. To address this issue, users should upgrade Jupiter X Core plugin to versions 4.9.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3888.
Read more CMSIn EventON Pro plugin versions up to and including 4.9.6 a medium severity vulnerability CVE-2025-3527 was detected. This vulnerability allows authenticated attackers with Subscriber-level access and above to inject arbitrary web scripts due to a missing capability check in the assets/lib/settings/settings.js file, leading to script execution when a user accesses an affected page. To address this issue, users should upgrade EventON Pro plugin to versions 4.9.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3527.
Read more CMSIn Firelight Lightbox plugin for WordPress versions prior to 2.3.15 a medium severity vulnerability CVE-2025-3597 was detected. This vulnerability lets authenticated users with post-writing access run harmful JavaScript when the jQuery Metadata feature is enabled, even in the free version of the plugin. To address this issue, users should upgrade Firelight Lightbox plugin to versions 2.3.15 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3597.
Read more CMS