WP Security

WP Security Vulnerability Report

569 posts
WWordPress Vulnerability Database

NEXForms Authenticated Admin SQL Injection Alert(CVE202510185)

  • October 11, 2025
WordPress NEX-Forms – Ultimate Forms Plugin for WordPress plugin <= 9.1.6 - Authenticated (Admin+) SQL Injection vulnerability
WWordPress Vulnerability Database

Community Alert Everest Backup Plugin Authorization Failure(CVE202511380)

  • October 10, 2025
WordPress Everest Backup plugin <= 2.3.5 - Missing Authorization to Unauthenticated Information Exposure vulnerability
WWordPress Vulnerability Database

Community Advisory WordPress JobHunt Authorization Bypass(CVE20257374)

  • October 9, 2025
WordPress WP JobHunt plugin <= 7.6 Authenticated (Custom+) Authorization Bypass vulnerability
WWordPress Vulnerability Database

Security Advisory TicketSpot Stored Cross Site Scripting(CVE20259875)

  • October 4, 2025
WordPress TicketSpot plugin <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database

Community Advisory Meks Easy Maps Stored XSS(CVE20259206)

  • October 4, 2025
WordPress Meks Easy Maps plugin <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database

HK Security Advisory Dynamics 365 CRM Vulnerability(CVE202510746)

  • October 4, 2025
WordPress Integrate Dynamics 365 CRM plugin <= 1.0.9 - Missing Authorization vulnerability
WWordPress Vulnerability Database

Constructor Plugin Authorization Flaw Threatens Community Sites(CVE20259194)

  • October 4, 2025
WordPress Constructor plugin <= 1.6.5 - Missing Authorization to Authenticated (Subscriber+) Theme Clean vulnerability
WWordPress Vulnerability Database

Security Advisory Backup Bolt Plugin File Download(CVE202510306)

  • October 4, 2025
WordPress Backup Bolt plugin <= 1.4.1 - Authenticated (Admin+) Arbitrary File Download vulnerability
WWordPress Vulnerability Database

GiveWP Donation Plugin Authorization Flaw Advisory(CVE202511228)

  • October 4, 2025
WordPress GiveWP – Donation Plugin and Fundraising Platform plugin <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association vulnerability
WWordPress Vulnerability Database

Hong Kong Alert WordPress File Upload Flaw(CVE20259212)

  • October 4, 2025
WordPress WP Dispatcher plugin <= 1.2.0 - Authenticated (Subscriber+) Arbitrary File Upload vulnerability
WP Security
© 2025 WP-Security.org Disclaimer: WP-Security.org is an independent, non-profit NGO community committed to sharing WordPress security news and information. We are not affiliated with WordPress, its parent company, or any related entities. All trademarks are the property of their respective owners.
en_USEnglish
zh_HKChinese (Hong Kong) zh_CNChinese (China) en_USEnglish

Review My Order

0

Subtotal

Taxes & shipping calculated at checkout

Checkout

 
0