WWordPress Vulnerability Database Hong Kong Security Alert Theater Plugin Risk(CVE202564259)November 15, 2025 WordPress Theater for WordPress plugin <= 0.18.8 - Broken Access Control vulnerability
WWordPress Vulnerability Database Contest Gallery Plugin Missing Authorization Vulnerability(CVE202512849)November 14, 2025 WordPress Contest Gallery plugin <= 28.0.2 - Missing Authorization vulnerability
WWordPress Vulnerability Database HK Security Advisory SEO Plugin Media Deletion(CVE202512847)November 14, 2025 WordPress All in One SEO plugin <= 4.8.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Deletion vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory Arbitrary Image Move(CVE202512494)November 14, 2025 WordPress Image Gallery – Photo Grid & Video Gallery plugin <= 2.12.28 - Improper Authorization to Authenticated (Author+) Arbitrary Image File Move vulnerability
WWordPress Vulnerability Database Community Security Alert Wishlist Plugin Deletion Flaw(CVE202512087)November 12, 2025 WordPress Wishlist and Save for later for Woocommerce plugin <= 1.1.22 - Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item Deletion vulnerability
WWordPress Vulnerability Database Add Multiple Marker Plugin Unauthorized Settings Risk(CVE202511999)November 11, 2025 WordPress Add Multiple Marker plugin <= 1.2 - Missing Authorization to Unauthenticated Settings Update vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert Unauthenticated Information Exposure(CVE202511997)November 10, 2025 WordPress Document Pro Elementor – Documentation & Knowledge Base plugin <= 1.0.9 - Unauthenticated Information Exposure vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert FunnelKit Vulnerability(CVE202510567)November 10, 2025 WordPress FunnelKit plugin < 3.12.0.1 - Reflected XSS vulnerability
WWordPress Vulnerability Database ZoloBlocks Access Control Vulnerability Community Advisory(CVE202549903)November 9, 2025 WordPress ZoloBlocks plugin <= 2.3.11 - Broken Access Control vulnerability
WWordPress Vulnerability Database Community Alert Easy Digital Downloads Order Risk(CVE202511271)November 9, 2025 WordPress Easy Digital Download plugin <= 3.5.2 - Insufficient Verification to Order Manipulation vulnerability