WBase de données des vulnérabilités WordPress Community Security Alert PowerBI Plugin Data Exposure(CVE202510750)octobre 18, 2025 WordPress PowerBI Embed Reports plugin <= 1.2.0 - Unauthenticated Sensitive Information Disclosure vulnerability
WBase de données des vulnérabilités WordPress Hong Kong Security Advisory Event Tickets Bypass(CVE202511517)octobre 18, 2025 WordPress Event Tickets and Registration plugin <= 5.26.5 - Unauthenticated Ticket Payment Bypass vulnerability
WBase de données des vulnérabilités WordPress Community Alert Theme Editor CSRF Enables RCE(CVE20259890)octobre 18, 2025 WordPress Theme Editor plugin <= 3.0 - Cross-Site Request Forgery to Remote Code Execution vulnerability
WBase de données des vulnérabilités WordPress Hong Kong Security Alert WordPress Map Injection(CVE202511365)octobre 16, 2025 WordPress WP Google Map Plugin plugin <= 1.0 - Authenticated (Contributor+) SQL Injection vulnerability
WBase de données des vulnérabilités WordPress HK Security Alert Quick Featured Images Flaw(CVE202511176)octobre 16, 2025 WordPress Quick Featured Images plugin <= 13.7.2 - Insecure Direct Object Reference to Image Manipulation vulnerability
WBase de données des vulnérabilités WordPress Hong Kong Security Advisory WordPress BlindMatrix LFI(CVE202510406)octobre 16, 2025 WordPress BlindMatrix e-Commerce plugin < 3.1 - Contributor+ LFI vulnerability
WBase de données des vulnérabilités WordPress Avis de la communauté Plugin Felan Identifiants codés en dur (CVE202510850)octobre 16, 2025 Plugin WordPress Felan Framework <= 1.1.4 - Vulnérabilité des identifiants codés en dur
WBase de données des vulnérabilités WordPress Public Security Notice Truelysell Password Vulnerability(CVE202510742)octobre 16, 2025 WordPress Truelysell Core plugin <= 1.8.6 - Unauthenticated Arbitrary User Password Change vulnerability
WBase de données des vulnérabilités WordPress Community Alert Felan Framework Unauthorised Plugin Activation(CVE202510849)octobre 16, 2025 WordPress Felan Framework plugin <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Activation/Deactivation via process_plugin_actions vulnerability
WBase de données des vulnérabilités WordPress Hong Kong Security Alert BookWidgets XSS(CVE202510139)octobre 15, 2025 WordPress WP BookWidgets plugin <= 0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability