In Ocean Extra plugin for WordPress versions up to and including 2.4.6 a medium severity vulnerability CVE-2025-3458 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the ocean_gallery_id parameter due to insufficient input sanitization and output escaping. To address this issue, users should upgrade Ocean Extra plugin to versions 2.4.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3458.
Read more CMSIn MemberPress plugin for WordPress versions up to and including 1.11.37 a medium severity vulnerability CVE-2024-11299 was detected. This vulnerability allows unauthenticated attackers to extract sensitive information from restricted posts via the WordPress core search feature. To address this issue, users should upgrade MemberPress plugin to versions 1.12.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11299.
Read more CMSIn WP Import Export Lite plugin for WordPress versions up to and including 3.9.27 a medium severity vulnerability CVE-2025-2839 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the wpiePreviewData function, due to insufficient input sanitization and output escaping. To address this issue, users should upgrade WP Import Export Lite plugin to versions 3.9.28 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2839.
Read more CMSIn Download Manager plugin for WordPress versions up to and including 3.3.12 a high severity vulnerability (CVE-2025-3404) was detected. This vulnerability allows authenticated attackers with Author-level access or higher to delete arbitrary files on the server via insufficient file path validation in the savePackage function, potentially leading to remote code execution if critical files like wp-config.php are removed. To address this issue, users should update Download Manager plugin to versions 3.3.13 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3404.
Read more CMSIn Debug Log Manager plugin for WordPress versions up to and including 2.3.4 a high severity vulnerability CVE-2025-3809 was detected. This vulnerability allows unauthenticated attackers to inject malicious JavaScript via the auto-refresh debug log due to insufficient input sanitization and output escaping. To address this issue, users should upgrade Debug Log Manager plugin to versions 2.3.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3809.
Read more CMSIn Liferay Portal versions 7.2.0 through 7.4.3.129 and Liferay DXP versions 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, 7.3 GA through update 36 and 7.2 GA through fix pack 20 a medium severity vulnerability CVE-2025-3760 was detected. This vulnerability allows remote authenticated attackers to inject malicious JavaScript into a page using radio button type custom fields. To address this issue, users should upgrade Liferay Portal to versions 7.4.3.132 and Liferay DXP to versions 2024.Q1.13, 2024.Q3.10 or 2025.Q1.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3760.
Read more CMSIn Embedder plugin for WordPress versions 1.3 to 1.3.5 a high severity vulnerability CVE-2025-3417 was detected. This vulnerability allows authenticated attackers with Subscriber-level access and above to modify data due to a missing capability check in the ajax_set_global_option() function, enabling them to change the default registration role to administrator and gain administrative access to the site. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3417.
Read more CMSIn ORDER POST plugin for WordPress versions 2.0.2 and prior a high severity vulnerability CVE-2025-2805 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary shortcodes due to improper validation of values before running do_shortcode. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2805.
Read more CMSIn Feedify plugin for WordPress versions prior to 2.4.6 a high severity vulnerability CVE-2024-13874 was detected. This vulnerability allows attackers to exploit a lack of sanitization and escaping of parameters, leading to Reflected Cross-Site Scripting (XSS) attacks that could target high-privilege users such as administrators. To address this issue, users should upgrade Feedify plugin to versions 2.4.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13874.
Read more CMS