WWordPress Vulnerability Database Hong Kong Security Avatar Migration Authorization Flaw(CVE20258482)August 11, 2025 WordPress Simple Local Avatars plugin <= 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Avatar Migration vulnerability
WWordPress Vulnerability Database Hong Kong Security WordPress Stock Quotes XSS(CVE20258688)August 11, 2025 WordPress Inline Stock Quotes plugin <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via stock Shortcode vulnerability
WWordPress Vulnerability Database Hong Kong Security NGO warns WordPress XSS(CVE20258685)August 11, 2025 WordPress Wp chart generator plugin <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpchart Shortcode vulnerability
WWordPress Vulnerability Database GMap Venturit Stored XSS Alert for HK(CVE20258568)August 11, 2025 WordPress GMap - Venturit plugin <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'h' Parameter vulnerability
WWordPress Vulnerability Database Authenticated CSV Injection in AnWP Football Leagues(CVE20258767)August 11, 2025 WordPress AnWP Football Leagues plugin <= 0.16.17 - Authenticated (Administrator+) CSV Injection vulnerability
WWordPress Vulnerability Database Hong Kong WordPress UiCore Unauthorised File Read(CVE20256253)August 11, 2025 WordPress UiCore Elements plugin <= 1.3.0 - Missing Authorization to Unauthenticated Arbitrary File Read vulnerability
WWordPress Vulnerability Database HK Security Alerts Elementor Image Import Flaw(CVE20258081)August 11, 2025 WordPress Elementor plugin <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import vulnerability
WWordPress Vulnerability Database Hong Kong security NGO flags CBX CSRF(CVE20257965)August 11, 2025 WordPress CBX Restaurant Booking plugin <= 1.2.1 - Plugin Reset via CSRF vulnerability
WWordPress Vulnerability Database Hong Kong WordPress The7 Stored XSS Alert(CVE20257726)August 11, 2025 WordPress The7 plugin <= 12.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via title and data-dt-img-description Attributes vulnerability
WWordPress Vulnerability Database Hong Kong Security Unauthenticated SQL Injection CleverReach(CVE20257036)August 11, 2025 WordPress CleverReach WP plugin <= 1.5.20 - Unauthenticated SQL Injection via title Parameter vulnerability