In the Orion Login with SMS plugin for WordPress versions up to and including 1.0.5 a high severity vulnerability CVE-2025-7692 was detected. This vulnerability allows unauthenticated attackers to log in as other users, including administrators, if they have access to their phone number, due to the olws_handle_verify_phone() function using a weak OTP value, exposing the hash used to generate it, and lacking restrictions on OTP submission attempts. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-7692.
Read more CMSIn the Latest Post Accordian Slider plugin for WordPress versions up to and including 1.3 a medium severity vulnerability CVE-2025-7687 was detected. This vulnerability allows unauthenticated attackers to update settings and inject malicious web scripts via a forged request, if they can trick a site administrator into performing an action such as clicking a link. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-7687.
Read more CMSIn WPLMS theme for WordPress versions 1.5.2 to 1.8.4.1 a high severity vulnerability CVE-2015-10139 was detected. This vulnerability allows authenticated attackers to escalate privileges by exploiting the unprotected wp_ajax_import_data AJAX action, enabling them to modify restricted settings and potentially create a new administrator account. To address this issue, users should upgrade WPLMS theme to versions 1.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2015-10139.
Read more CMSIn Work The Flow File Upload plugin for WordPress versions up to and including 2.5.2 a critical severity vulnerability CVE-2015-10138 was detected. This vulnerability allows unauthenticated attackers to upload arbitrary files due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files, potentially leading to remote code execution. To address this issue, users should upgrade Work The Flow File Upload plugin to versions 2.5.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2015-10138.
Read more CMSIn WP Mobile Detector plugin for WordPress versions up to and including 3.5 a critical severity vulnerability CVE-2016-15043 was detected. This vulnerability allows unauthenticated attackers to upload arbitrary files due to missing file type validation in the resize.php file, potentially leading to remote code execution. To address this issue, users should upgrade WP Mobile Detector plugin to versions 3.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2016-15043.
Read more CMSIn GI-Media Library plugin for WordPress versions prior to 3.0 a high severity vulnerability CVE-2015-10136 was detected. This vulnerability allows unauthenticated attackers to read the contents of arbitrary files on the server via directory traversal using the fileid parameter, potentially exposing sensitive information. To address this issue, users should upgrade GI-Media Library plugin to version 3.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2015-10136.
Read more CMSIn Directus versions 9.12.0 and above a medium severity vulnerability CVE-2025-53889 was detected. This vulnerability allows attackers to execute manual trigger Flows without authentication or proper access rights, potentially performing unauthorized actions on behalf of a user. To address this issue, users should upgrade Directus to version 11.9.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53889.
Read more CMSIn Directus versions 9.0.0 and above a medium severity vulnerability CVE-2025-53887 was detected. This vulnerability allows attackers to obtain the exact Directus version via the unauthenticated /server/specs/oas endpoint, potentially aiding in targeted exploitation using known vulnerabilities. To address this issue, users should upgrade Directus to version 11.9.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53887.
Read more CMSIn Directus versions 9.0.0 and above a medium severity vulnerability CVE-2025-53886 was detected. This vulnerability allows malicious administrators to hijack user sessions by accessing sensitive data such as access and refresh tokens logged during Flow WebHook executions. To address this issue, users should upgrade Directus to version 11.9.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53886.
Read more CMS