WWordPress Vulnerability Database Urgent Alert ERI File Library Unauthenticated Access(CVE202512041)November 1, 2025 WordPress ERI File Library plugin <= 1.1.0 - Missing Authorization to Unauthenticated Protected File Download vulnerability
WWordPress Vulnerability Database Hong Kong Cybersecurity Alert Analytify Information Exposure(CVE202512521)November 1, 2025 WordPress Analytify Pro plugin <= 7.0.3 - Unauthenticated Information Exposure vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory Jobmonster Authentication Bypass(CVE20255397)November 1, 2025 WordPress Jobmonster theme <= 4.8.1 - Authentication Bypass vulnerability
WWordPress Vulnerability Database Protect Hong Kong Sites From ERI Exploit(CVE202512041)November 1, 2025 WordPress ERI File Library plugin <= 1.1.0 - Missing Authorization to Unauthenticated Protected File Download vulnerability
WWordPress Vulnerability Database Community Security Advisory Unauthenticated Log Poisoning(CVE202511627)October 31, 2025 WordPress Site Checkup AI Troubleshooting with Wizard and Tips for Each Issue plugin <= 1.47 - Unauthenticated Log File Poisoning vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert Authenticated File Deletion(CVE20257846)October 31, 2025 WordPress User Extra Fields plugin <= 16.7 - Authenticated (Subscriber+) Arbitrary File Deletion via save_fields Function vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert WooCommerce Data Exposure(CVE20237320)October 29, 2025 WordPress WooCommerce plugin <= 7.8.2 - Sensitive Information Exposure vulnerability
WWordPress Vulnerability Database Community Alert CSRF Risk in WordPress Sync(CVE202511976)October 28, 2025 WordPress FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin <= 1.1.23.0 - Cross-Site Request Forgery to Sync Rule Creation vulnerability
WWordPress Vulnerability Database Hong Kong Alert Listeo Stored XSS Threat(CVE20258413)October 28, 2025 WordPress Listeo plugin <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via soundcloud Shortcode vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert GenerateBlocks Options Exposure(CVE202511879)October 25, 2025 WordPress GenerateBlocks plugin <= 2.1.1 - Improper Authorization to Authenticated (Contributor+) Arbitrary Options Disclosure vulnerability