WWordPress Vulnerability Database HK NGO warns WordPress CSRF Object Injection(CVE202549895)August 16, 2025 WordPress ServerBuddy by PluginBuddy.com plugin <= 1.0.5 - CSRF to PHP Object Injection vulnerability
WWordPress Vulnerability Database Hong Kong Security WordPress Profile Builder XSS(CVE20258896)August 16, 2025 Plugin Name Profile Builder Type of Vulnerability Stored XSS CVE Number CVE-2025-8896 Urgency Medium CVE Publish Date 2025-08-16…
WWordPress Vulnerability Database WordPress BetterDocs Privacy Flaw Exposes Private Posts(CVE20257499)August 16, 2025 Plugin Name BetterDocs Type of Vulnerability Broken Access Control CVE Number CVE-2025-7499 Urgency Low CVE Publish Date 2025-08-16…
WWordPress Vulnerability Database Hong Kong Security NGO alerts Soledad LFI(CVE20258142)August 16, 2025 WordPress Soledad plugin <= 8.6.7 - Authenticated (Contributor+) Local File Inclusion via 'header_layout' vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert WordPress iFrame XSS(CVE20258089)August 16, 2025 WordPress Advanced iFrame plugin <= 2025.6 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory WordPress Soledad Stored XSS(CVE20258143)August 16, 2025 WordPress Soledad plugin <= 8.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pcsml_smartlists_h' vulnerability
WWordPress Vulnerability Database Hong Kong Security NGO Warns Unauthenticated Shortcode(CVE20258105)August 16, 2025 WordPress Soledad plugin <= 8.6.7 - Unauthenticated Arbitrary Shortcode Execution vulnerability
WWordPress Vulnerability Database Hong Kong NGO warns ProfilePress shortcode vulnerability(CVE20258878)August 16, 2025 WordPress ProfilePress plugin <= 4.16.4 - Unauthenticated Arbitrary Shortcode Execution vulnerability
WWordPress Vulnerability Database HK Security NGO Warns CF7 Directory Traversal(CVE20258464)August 16, 2025 WordPress Drag and Drop Multiple File Upload for Contact Form 7 plugin <= 1.3.9.0 - Directory Traversal via `wpcf7_guest_user_id` Cookie vulnerability
WWordPress Vulnerability Database Hong Kong Security NGO Alerts WPGYM LFI(CVE20253671)August 16, 2025 WordPress WPGYM - Wordpress Gym Management System plugin <= 67.7.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update vulnerability