WWordPress Vulnerability Database HK Security Alert Quick Featured Images Flaw(CVE202511176)October 16, 2025 WordPress Quick Featured Images plugin <= 13.7.2 - Insecure Direct Object Reference to Image Manipulation vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Advisory WordPress BlindMatrix LFI(CVE202510406)October 16, 2025 WordPress BlindMatrix e-Commerce plugin < 3.1 - Contributor+ LFI vulnerability Read More
WWordPress Vulnerability Database Community Notice Felan Plugin Hardcoded Credentials(CVE202510850)October 16, 2025 WordPress Felan Framework plugin <= 1.1.4 - Hardcoded Credentials vulnerability Read More
WWordPress Vulnerability Database Public Security Notice Truelysell Password Vulnerability(CVE202510742)October 16, 2025 WordPress Truelysell Core plugin <= 1.8.6 - Unauthenticated Arbitrary User Password Change vulnerability Read More
WWordPress Vulnerability Database Community Alert Felan Framework Unauthorised Plugin Activation(CVE202510849)October 16, 2025 WordPress Felan Framework plugin <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Activation/Deactivation via process_plugin_actions vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Alert BookWidgets XSS(CVE202510139)October 15, 2025 WordPress WP BookWidgets plugin <= 0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability Read More
WWordPress Vulnerability Database Community Advisory WPBakery Stored Cross Site Scripting(CVE202511160)October 15, 2025 WordPress WPBakery Page Builder plugin <= 8.6.1 - Stored Cross-Site Scripting via Custom JS Module vulnerability Read More
WWordPress Vulnerability Database Hong Kong Alert Simple SEO Stored XSS(CVE202510357)October 15, 2025 WordPress Simple SEO plugin < 2.0.32 - Contributor+ Stored XSS vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Advisory Zip Attachments Deletion(CVE202511692)October 15, 2025 WordPress Zip Attachments plugin <= 1.6 - Missing Authorization to Limited File Deletion vulnerability Read More
WWordPress Vulnerability Database Community Security Alert Keyy Two Factor Vulnerability(CVE202510293)October 15, 2025 WordPress Keyy Two Factor Authentication (like Clef) plugin <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover vulnerability Read More