WWordPress Vulnerability Database Hong Kong Cybersecurity Alert onOffice SQL Injection(CVE202510045)October 15, 2025 WordPress onOffice for WP-Websites plugin <= 5.7 - Authenticated (Editor+) SQL Injection vulnerability
WWordPress Vulnerability Database Hong Kong Advisory TopBar CSRF Vulnerability(CVE202510300)October 15, 2025 WordPress TopBar plugin <= 1.0.0 - Cross-Site Request Forgery to Settings Update vulnerability
WWordPress Vulnerability Database Community Alert Ova Advent Stored XSS(CVE20258561)October 15, 2025 WordPress Ova Advent plugin <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert File Deletion Risk(CVE202511692)October 15, 2025 WordPress Zip Attachments plugin <= 1.6 - Missing Authorization to Limited File Deletion vulnerability
WWordPress Vulnerability Database Community Alert Flex QR Plugin Upload Risk(CVE202510041)October 15, 2025 WordPress Flex QR Code Generator plugin <= 1.2.5 - Unauthenticated Arbitrary File Upload vulnerability
WWordPress Vulnerability Database Community Alert OwnID Authentication Bypass(CVE202510294)October 15, 2025 WordPress OwnID Passwordless Login plugin <= 1.3.4 - Authentication Bypass vulnerability
WWordPress Vulnerability Database Security Alert WordPress Zip Attachment Exposure(CVE202511701)October 15, 2025 WordPress Zip Attachments plugin <= 1.6 - Missing Authorization to Unauthenticated Private And Password-Protected Posts Attachment Disclosure vulnerability
WWordPress Vulnerability Database Public Advisory Theme Importer CSRF Vulnerability(CVE202510312)October 15, 2025 WordPress Theme Importer plugin <= 1.0 - Cross-Site Request Forgery vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert Lisfinity Privilege Escalation(CVE20256042)October 15, 2025 WordPress Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin <= 1.4.0 - Unauthenticated Privilege Escalation to Editor vulnerability
WWordPress Vulnerability Database Oceanpayment Plugin Permits Unauthenticated Order Status Changes(CVE202511728)October 15, 2025 WordPress Oceanpayment CreditCard Gateway plugin <= 6.0 - Missing Authentication to Unauthenticated Order Status Update vulnerability