WBase de Datos de Vulnerabilidades de WordPress Community Security Alert PowerBI Plugin Data Exposure(CVE202510750)octubre 18, 2025 WordPress PowerBI Embed Reports plugin <= 1.2.0 - Unauthenticated Sensitive Information Disclosure vulnerability
WBase de Datos de Vulnerabilidades de WordPress Hong Kong Security Advisory Event Tickets Bypass(CVE202511517)octubre 18, 2025 WordPress Event Tickets and Registration plugin <= 5.26.5 - Unauthenticated Ticket Payment Bypass vulnerability
WBase de Datos de Vulnerabilidades de WordPress Community Alert Theme Editor CSRF Enables RCE(CVE20259890)octubre 18, 2025 WordPress Theme Editor plugin <= 3.0 - Cross-Site Request Forgery to Remote Code Execution vulnerability
WBase de Datos de Vulnerabilidades de WordPress Hong Kong Security Alert WordPress Map Injection(CVE202511365)octubre 16, 2025 WordPress WP Google Map Plugin plugin <= 1.0 - Authenticated (Contributor+) SQL Injection vulnerability
WBase de Datos de Vulnerabilidades de WordPress Alerta de seguridad de HK Fallo en Quick Featured Images(CVE202511176)octubre 16, 2025 Plugin Quick Featured Images de WordPress <= 13.7.2 - Vulnerabilidad de referencia de objeto directo insegura para la manipulación de imágenes
WBase de Datos de Vulnerabilidades de WordPress Hong Kong Security Advisory WordPress BlindMatrix LFI(CVE202510406)octubre 16, 2025 WordPress BlindMatrix e-Commerce plugin < 3.1 - Contributor+ LFI vulnerability
WBase de Datos de Vulnerabilidades de WordPress Community Notice Felan Plugin Hardcoded Credentials(CVE202510850)octubre 16, 2025 WordPress Felan Framework plugin <= 1.1.4 - Hardcoded Credentials vulnerability
WBase de Datos de Vulnerabilidades de WordPress Public Security Notice Truelysell Password Vulnerability(CVE202510742)octubre 16, 2025 WordPress Truelysell Core plugin <= 1.8.6 - Unauthenticated Arbitrary User Password Change vulnerability
WBase de Datos de Vulnerabilidades de WordPress Community Alert Felan Framework Unauthorised Plugin Activation(CVE202510849)octubre 16, 2025 WordPress Felan Framework plugin <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Activation/Deactivation via process_plugin_actions vulnerability
WBase de Datos de Vulnerabilidades de WordPress Hong Kong Security Alert BookWidgets XSS(CVE202510139)octubre 15, 2025 WordPress WP BookWidgets plugin <= 0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability