WP Security

WP Security Vulnerability Report

571 posts
WWordPress Vulnerability Database

GiveWP Donation Plugin Authorization Flaw Advisory(CVE202511228)

  • October 4, 2025
WordPress GiveWP – Donation Plugin and Fundraising Platform plugin <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association vulnerability
WWordPress Vulnerability Database

Hong Kong Alert WordPress File Upload Flaw(CVE20259212)

  • October 4, 2025
WordPress WP Dispatcher plugin <= 1.2.0 - Authenticated (Subscriber+) Arbitrary File Upload vulnerability
WWordPress Vulnerability Database

Hong Kong Advisory Ird Slider Stored XSS(CVE20259876)

  • October 4, 2025
WordPress Ird Slider plugin <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database

Community Alert Meks Easy Maps Stored XSS(CVE20259206)

  • October 4, 2025
WordPress Meks Easy Maps plugin <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database

Community Alert Backup Bolt Arbitrary File Download(CVE202510306)

  • October 4, 2025
WordPress Backup Bolt plugin <= 1.4.1 - Authenticated (Admin+) Arbitrary File Download vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert Notification Bar CSRF(CVE20259895)

  • October 4, 2025
WordPress Notification Bar plugin <= 2.2 - Cross-Site Request Forgery vulnerability
WWordPress Vulnerability Database

Community Alert WPRecovery SQL Injection Threat(CVE202510726)

  • October 4, 2025
WordPress WPRecovery plugin <= 2.0 - Unauthenticated SQL Injection to Arbitrary File Deletion vulnerability
WWordPress Vulnerability Database

Hong Kong Security Notice Missing Plugin Authorization(CVE202510746)

  • October 4, 2025
WordPress Integrate Dynamics 365 CRM plugin <= 1.0.9 - Missing Authorization vulnerability
WWordPress Vulnerability Database

Security Advisory Restrict User Registration CSRF(CVE20259892)

  • October 3, 2025
WordPress Restrict User Registration plugin <= 1.0.1 - Cross-Site Request Forgery to Settings Update vulnerability
WWordPress Vulnerability Database

ContentMX Plugin CSRF Community Advisory(CVE20259889)

  • October 3, 2025
WordPress ContentMX Content Publisher plugin <= 1.0.6 - Cross-Site Request Forgery vulnerability
WP Security
© 2025 WP-Security.org Disclaimer: WP-Security.org is an independent, non-profit NGO community committed to sharing WordPress security news and information. We are not affiliated with WordPress, its parent company, or any related entities. All trademarks are the property of their respective owners.
en_USEnglish
zh_HKChinese (Hong Kong) zh_CNChinese (China) en_USEnglish

Review My Order

0

Subtotal

Taxes & shipping calculated at checkout

Checkout

 
0