WBase de Datos de Vulnerabilidades de WordPress Hong Kong Security NGO WordPress Import XSS(CVE20258490)agosto 26, 2025 WordPress All-in-One WP Migration and Backup plugin <= 7.97 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import vulnerability
WBase de Datos de Vulnerabilidades de WordPress Stored XSS in Lazy Load Videos Plugin(CVE20257732)agosto 26, 2025 WordPress Lazy Load for Videos plugin <= 2.18.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via data-video-title and href Attributes vulnerability
WBase de Datos de Vulnerabilidades de WordPress Aviso de Seguridad de Hong Kong Escalación de Privilegios Dokan Pro(CVE20255931)agosto 26, 2025 Plugin Dokan Pro de WordPress <= 4.0.5 - Vulnerabilidad de Escalación de Privilegios Autenticada (Proveedor+)
WBase de Datos de Vulnerabilidades de WordPress Community Security Advisory SiteSEO Stored XSS(CVE20259277)agosto 26, 2025 WordPress SiteSEO plugin <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Broken Regex Expression vulnerability
WBase de Datos de Vulnerabilidades de WordPress Hong Kong Security Advisory Shortcode Path Traversal(CVE20258562)agosto 26, 2025 Urgent: Directory Traversal in ‘Custom Query Shortcode’ (≤ 0.4.0) — What WordPress Site Owners Need to Know and…
WBase de Datos de Vulnerabilidades de WordPress Plugin Tourfic Falta de Autorización Debilita la Seguridad del Sitio (CVE20248860)agosto 26, 2025 Tourfic
WBase de Datos de Vulnerabilidades de WordPress Hong Kong Security Notice Event List Escalation(CVE20256366)agosto 26, 2025 WordPress Event List plugin <= 2.0.4 - Authenticated (Subscriber+) Privilege Escalation vulnerability
WBase de Datos de Vulnerabilidades de WordPress Alerta de seguridad de Hong Kong plugin CSRF XSS (CVE20256247)agosto 26, 2025 WordPress WordPress Automatic plugin <= 3.118.0 - Vulnerabilidad de Cross-Site Request Forgery a Cross-Site Scripting almacenado
WBase de Datos de Vulnerabilidades de WordPress Community Advisory Vibes Plugin SQL Injection Vulnerability(CVE20259172)agosto 26, 2025 WordPress Vibes plugin <= 2.2.0 - Unauthenticated SQL Injection via `resource` Parameter vulnerability
WBase de Datos de Vulnerabilidades de WordPress Community Security Alert CSRF in WordPress Plugin(CVE202548303)agosto 25, 2025 WordPress Post Type Converter plugin <= 0.6 - Cross Site Request Forgery (CSRF) vulnerability