WP Security

WP Security Vulnerability Report

571 posts
WWordPress Vulnerability Database

Hong Kong Security Alert WordPress Stored XSS(CVE20259077)

  • October 3, 2025
WordPress Ultra Addons Lite for Elementor plugin <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Field vulnerability
WWordPress Vulnerability Database

Community Advisory WordPress Dispatcher SQL Injection(CVE202510582)

  • October 3, 2025
WordPress WP Dispatcher plugin <= 1.2.0 - Authenticated (Contributor+) SQL Injection vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert WP Dispatcher Vulnerability(CVE20259212)

  • October 3, 2025
WordPress WP Dispatcher plugin <= 1.2.0 - Authenticated (Subscriber+) Arbitrary File Upload vulnerability
WWordPress Vulnerability Database

Hong Kong Security Advisory Flexi Plugin XSS(CVE20259129)

  • October 3, 2025
WordPress Flexi plugin <= 4.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via flexi-form-tag Shortcode vulnerability
WWordPress Vulnerability Database

Community Alert JoomSport Directory Traversal Vulnerability(CVE20257721)

  • October 3, 2025
WordPress JoomSport plugin <= 5.7.3 - Unauthenticated Directory Traversal to Local File Inclusion vulnerability
WWordPress Vulnerability Database

Hong Kong Security Advisory MPWizard CSRF Risk(CVE20259885)

  • October 3, 2025
WordPress MPWizard plugin <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post Deletion vulnerability
WWordPress Vulnerability Database

Hong Kong Advisory ZoloBlocks Stored XSS Risk(CVE20259075)

  • September 30, 2025
WordPress ZoloBlocks plugin <= 2.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database

Alert Managefy Plugin Information Exposure Risk(CVE202510744)

  • September 30, 2025
WordPress File Manager, Code editor, backup by Managefy plugin <= 1.6.1 - Unauthenticated Information Exposure vulnerability
WWordPress Vulnerability Database

Hong Kong Alert CSRF to Stored XSS(CVE20259946)

  • September 30, 2025
WordPress LockerPress – WordPress Security Plugin plugin <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database

Community Alert LatePoint Authentication Bypass Risk(CVE20257038)

  • September 30, 2025
WordPress LatePoint plugin <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function vulnerability
WP Security
© 2025 WP-Security.org Disclaimer: WP-Security.org is an independent, non-profit NGO community committed to sharing WordPress security news and information. We are not affiliated with WordPress, its parent company, or any related entities. All trademarks are the property of their respective owners.
en_USEnglish
zh_HKChinese (Hong Kong) zh_CNChinese (China) en_USEnglish

Review My Order

0

Subtotal

Taxes & shipping calculated at checkout

Checkout

 
0