WBase de Datos de Vulnerabilidades de WordPress HK Security Advisory SEO Plugin Media Deletion(CVE202512847)noviembre 14, 2025 WordPress All in One SEO plugin <= 4.8.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Deletion vulnerability
WBase de Datos de Vulnerabilidades de WordPress Hong Kong Security Advisory Arbitrary Image Move(CVE202512494)noviembre 14, 2025 WordPress Image Gallery – Photo Grid & Video Gallery plugin <= 2.12.28 - Improper Authorization to Authenticated (Author+) Arbitrary Image File Move vulnerability
WBase de Datos de Vulnerabilidades de WordPress Community Security Alert Wishlist Plugin Deletion Flaw(CVE202512087)noviembre 12, 2025 WordPress Wishlist and Save for later for Woocommerce plugin <= 1.1.22 - Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item Deletion vulnerability
WBase de Datos de Vulnerabilidades de WordPress Add Multiple Marker Plugin Unauthorized Settings Risk(CVE202511999)noviembre 11, 2025 WordPress Add Multiple Marker plugin <= 1.2 - Missing Authorization to Unauthenticated Settings Update vulnerability
WBase de Datos de Vulnerabilidades de WordPress Hong Kong Security Alert Unauthenticated Information Exposure(CVE202511997)noviembre 10, 2025 WordPress Document Pro Elementor – Documentation & Knowledge Base plugin <= 1.0.9 - Unauthenticated Information Exposure vulnerability
WBase de Datos de Vulnerabilidades de WordPress Alerta de seguridad de Hong Kong Vulnerabilidad FunnelKit(CVE202510567)noviembre 10, 2025 Plugin FunnelKit de WordPress < 3.12.0.1 - Vulnerabilidad de XSS reflejado
WBase de Datos de Vulnerabilidades de WordPress ZoloBlocks Access Control Vulnerability Community Advisory(CVE202549903)noviembre 9, 2025 WordPress ZoloBlocks plugin <= 2.3.11 - Broken Access Control vulnerability
WBase de Datos de Vulnerabilidades de WordPress Alerta comunitaria Riesgo de pedido de Easy Digital Downloads (CVE202511271)noviembre 9, 2025 Plugin Easy Digital Download de WordPress <= 3.5.2 - Vulnerabilidad de verificación insuficiente para la manipulación de pedidos
WBase de Datos de Vulnerabilidades de WordPress Public Security Advisory Events Calendar SQL Injection(CVE202512197)noviembre 8, 2025 WordPress The Events Calendar plugin 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s vulnerability
WBase de Datos de Vulnerabilidades de WordPress Community Advisory LC Wizard Plugin Authorization Flaw(CVE20255483)noviembre 7, 2025 WordPress LC Wizard plugin 1.2.10 - 1.3.0 - Missing Authorization to Unauthenticated Privilege Escalation vulnerability