WWordPress Vulnerability Database Hong Kong Security Alert WordPress Map Injection(CVE202511365)October 16, 2025 WordPress WP Google Map Plugin plugin <= 1.0 - Authenticated (Contributor+) SQL Injection vulnerability
WWordPress Vulnerability Database HK Security Alert Quick Featured Images Flaw(CVE202511176)October 16, 2025 WordPress Quick Featured Images plugin <= 13.7.2 - Insecure Direct Object Reference to Image Manipulation vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory WordPress BlindMatrix LFI(CVE202510406)October 16, 2025 WordPress BlindMatrix e-Commerce plugin < 3.1 - Contributor+ LFI vulnerability
WWordPress Vulnerability Database Community Notice Felan Plugin Hardcoded Credentials(CVE202510850)October 16, 2025 WordPress Felan Framework plugin <= 1.1.4 - Hardcoded Credentials vulnerability
WWordPress Vulnerability Database Public Security Notice Truelysell Password Vulnerability(CVE202510742)October 16, 2025 WordPress Truelysell Core plugin <= 1.8.6 - Unauthenticated Arbitrary User Password Change vulnerability
WWordPress Vulnerability Database Community Alert Felan Framework Unauthorised Plugin Activation(CVE202510849)October 16, 2025 WordPress Felan Framework plugin <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Activation/Deactivation via process_plugin_actions vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert BookWidgets XSS(CVE202510139)October 15, 2025 WordPress WP BookWidgets plugin <= 0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database Community Advisory WPBakery Stored Cross Site Scripting(CVE202511160)October 15, 2025 WordPress WPBakery Page Builder plugin <= 8.6.1 - Stored Cross-Site Scripting via Custom JS Module vulnerability
WWordPress Vulnerability Database Hong Kong Alert Simple SEO Stored XSS(CVE202510357)October 15, 2025 WordPress Simple SEO plugin < 2.0.32 - Contributor+ Stored XSS vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory Zip Attachments Deletion(CVE202511692)October 15, 2025 WordPress Zip Attachments plugin <= 1.6 - Missing Authorization to Limited File Deletion vulnerability