In Ocean Extra plugin for WordPress versions up to and including 2.4.6 a medium severity vulnerability CVE-2025-3472 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary shortcodes due to improper validation before calling do_shortcode, when WooCommerce is also installed and active. To address this issue, users should upgrade Ocean Extra plugin to versions 2.4.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3472.
Read more CMSIn Ocean Extra plugin for WordPress versions up to and including 2.4.6 a medium severity vulnerability CVE-2025-3458 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the ocean_gallery_id parameter due to insufficient input sanitization and output escaping. To address this issue, users should upgrade Ocean Extra plugin to versions 2.4.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3458.
Read more CMSIn MemberPress plugin for WordPress versions up to and including 1.11.37 a medium severity vulnerability CVE-2024-11299 was detected. This vulnerability allows unauthenticated attackers to extract sensitive information from restricted posts via the WordPress core search feature. To address this issue, users should upgrade MemberPress plugin to versions 1.12.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11299.
Read more CMSIn Traefik versions prior to 2.11.24, 3.3.6 and 3.4.0-rc2 a high severity vulnerability CVE-2025-32431 was detected. This vulnerability allows attackers to bypass middleware chains by exploiting path matchers (PathPrefix, Path, or PathRegex) when a request URL contains `/../`, potentially targeting unintended backends. To address this issue, users should upgrade Traefik to versions 2.11.24, 3.3.6 or 3.4.0-rc2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-32431.
Read more SecurityIn WP Import Export Lite plugin for WordPress versions up to and including 3.9.27 a medium severity vulnerability CVE-2025-2839 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the wpiePreviewData function, due to insufficient input sanitization and output escaping. To address this issue, users should upgrade WP Import Export Lite plugin to versions 3.9.28 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2839.
Read more CMSIn MySQL Cluster versions 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0 a medium severity vulnerability CVE-2025-30710 was detected. This vulnerability allows high-privileged attackers with network access via multiple protocols to compromise MySQL Cluster, potentially causing a hang or repeatable crash (complete DOS). Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-30710.
Read more Database