In Simple Logo Carousel plugin for WordPress versions up to and including 1.9.3 a medium severity vulnerability CVE-2025-5700 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via the ‘id’ parameter due to insufficient input sanitization and output escaping. To address this issue, users should upgrade Simple Logo Carousel plugin to versions 1.9.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5700.
Read more CMSIn Ivory Search plugin for WordPress versions before 5.5.10 a low severity vulnerability CVE-2025-5209 was detected. This vulnerability allows high privilege users, such as administrators, to perform Cross-Site Scripting (XSS) attacks due to insufficient sanitization and escaping of certain settings, even when the unfiltered_html capability is disallowed. To address this issue, users should upgrade Ivory Search plugin to versions 5.5.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5209.
Read more CMSIn Hide It plugin for WordPress versions up to and including 1.0.1 a medium severity vulnerability CVE-2025-5565 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject malicious scripts via the plugin’s hideit shortcode due to insufficient input sanitization and output escaping. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5565.
Read more CMSIn WP-Addpub plugin for WordPress versions up to and including 1.2.8 a medium severity vulnerability CVE-2025-5563 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to extract sensitive information from the database via SQL Injection through the wp-addpub shortcode, due to insufficient input escaping and improper SQL query preparation. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5563.
Read more CMSIn Runners Log plugin for WordPress versions up to and including 3.9.2 a medium severity vulnerability CVE-2025-5541 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject malicious scripts via the runnerslog shortcode due to insufficient input sanitization and output escaping. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5541.
Read more CMSIn BNS Featured Category plugin for WordPress versions up to and including 2.8.2 a medium severity vulnerability CVE-2025-5538 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject malicious scripts via the bnsfc shortcode due to insufficient input sanitization and output escaping. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5538.
Read more CMSIn Freemind Viewer plugin for WordPress versions up to and including 1.0 a medium severity vulnerability CVE-2025-5536 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject malicious scripts via the freemind shortcode due to insufficient input sanitization and output escaping. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5536.
Read more CMSIn Developer Formatter plugin for WordPress versions up to and including 2015.0.2.1 a medium severity vulnerability CVE-2025-5699 was detected. This vulnerability allows authenticated attackers with Administrator-level access to inject malicious scripts via the Custom CSS field due to insufficient input sanitization and output escaping, affecting only multisite installations or sites where unfiltered_html is disabled. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5699.
Read more CMSIn Paged Gallery plugin for WordPress versions up to and including 0.7 a medium severity vulnerability CVE-2025-5686 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject malicious scripts via the gallery shortcode due to insufficient input sanitization and output escaping. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5686.
Read more CMS