WWordPress Vulnerability Database Hong Kong Alerts WordPress CSRF To XSS(CVE20257686)August 16, 2025 Plugin Name weichuncai(WP伪春菜) Type of Vulnerability Stored XSS CVE Number CVE-2025-7686 Urgency Medium CVE Publish Date 2025-08-15 Source…
WWordPress Vulnerability Database Hong Kong Security WordPress README Parser XSS(CVE20258720)August 16, 2025 WordPress Plugin README Parser plugin <= 1.3.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via target Parameter vulnerability
WWordPress Vulnerability Database HK Security NGO alerts NextGEN Directory Deletion(CVE20257641)August 16, 2025 WordPress Assistant for NextGEN Gallery plugin <= 1.0.9 - Unauthenticated Arbitrary Directory Deletion vulnerability
WWordPress Vulnerability Database HK Security Alert WordPress AI Pack Bypass(CVE20257664)August 16, 2025 WordPress Al Pack plugin <= 1.0.2 - Missing Authorization to Unauthenticated Premium Feature Activation via check_activate_permission Function vulnerability
WWordPress Vulnerability Database HK Security NGO warns WordPress Surbma XSS(CVE20257649)August 16, 2025 WordPress Surbma | Recent Comments Shortcode plugin <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert StoryChief Unauthenticated Upload(CVE20257441)August 16, 2025 WordPress StoryChief plugin <= 1.0.42 - Unauthenticated Arbitrary File Upload vulnerability
WWordPress Vulnerability Database HK Security Alert Unauthenticated Poll Maker Data(CVE202412575)August 16, 2025 WordPress Poll Maker plugin <= 5.8.9 - Unauthenticated Basic Information Exposure vulnerability
WWordPress Vulnerability Database HK Security NGO Warns WordPress Validation Flaw(CVE20257507)August 16, 2025 WordPress elink – Embed Content plugin <= 1.1.0 - Authenticated (Contributor+) Insufficient Input Validation vulnerability
WWordPress Vulnerability Database HK NGO Alerts WordPress Earnware Connect XSS(CVE20257651)August 16, 2025 WordPress Earnware Connect plugin <= 1.0.73 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database WordPress User Meta CSRF Exposes Stored XSS(CVE20257688)August 16, 2025 WordPress Add User Meta plugin <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability