WP Security

WP Security Vulnerability Report

571 posts
WWordPress Vulnerability Database

Professional Contact Form CSRF Alert(CVE20259944)

  • September 27, 2025
WordPress Professional Contact Form plugin <= 1.0.0 - Cross-Site Request Forgery to Test Email Sending vulnerability
WWordPress Vulnerability Database

Hong Kong Advisory Ninja Forms CSRF Threat(CVE202510499)

  • September 27, 2025
WordPress Ninja Forms plugin <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert WordPress Statistics XSS(CVE20259816)

  • September 27, 2025
WordPress WP Statistics plugin <= 14.5.4 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header vulnerability
WWordPress Vulnerability Database

Hong Kong Security Notice wpmpdf XSS Risk(CVE202560040)

  • September 26, 2025
WordPress wp-mpdf Plugin <= 3.9.1 - Cross Site Scripting (XSS) Vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert Vehica CSRF Vulnerability(CVE202560117)

  • September 26, 2025
WordPress Vehica Core Plugin <= 1.0.100 - Cross Site Request Forgery (CSRF) Vulnerability
WWordPress Vulnerability Database

Community Alert XSS in Support Ticket Plugin(CVE202560157)

  • September 26, 2025
WordPress WP Ticket Customer Service Software & Support Ticket System Plugin <= 6.0.2 - Cross Site Scripting (XSS) Vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert Mega Elements XSS(CVE20258200)

  • September 26, 2025
WordPress Mega Elements plugin <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert OAuth SSO Vulnerability(CVE202510752)

  • September 26, 2025
WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 6.26.12 - Cross-Site Request Forgery vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert Tiktok Feed XSS(CVE20258906)

  • September 25, 2025
WordPress Widgets for Tiktok Feed plugin <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database

Themify Builder Stored Cross Site Scripting Vulnerability(CVE20259353)

  • September 24, 2025
WordPress Themify Builder plugin <= 7.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WP Security
© 2025 WP-Security.org Disclaimer: WP-Security.org is an independent, non-profit NGO community committed to sharing WordPress security news and information. We are not affiliated with WordPress, its parent company, or any related entities. All trademarks are the property of their respective owners.
en_USEnglish
zh_HKChinese (Hong Kong) zh_CNChinese (China) en_USEnglish

Review My Order

0

Subtotal

Taxes & shipping calculated at checkout

Checkout

 
0