WBase de données des vulnérabilités WordPress Community Advisory WPBakery Stored Cross Site Scripting(CVE202511160)octobre 15, 2025 WordPress WPBakery Page Builder plugin <= 8.6.1 - Stored Cross-Site Scripting via Custom JS Module vulnerability
WBase de données des vulnérabilités WordPress Hong Kong Alert Simple SEO Stored XSS(CVE202510357)octobre 15, 2025 WordPress Simple SEO plugin < 2.0.32 - Contributor+ Stored XSS vulnerability
WBase de données des vulnérabilités WordPress Hong Kong Security Advisory Zip Attachments Deletion(CVE202511692)octobre 15, 2025 WordPress Zip Attachments plugin <= 1.6 - Missing Authorization to Limited File Deletion vulnerability
WBase de données des vulnérabilités WordPress Community Security Alert Keyy Two Factor Vulnerability(CVE202510293)octobre 15, 2025 WordPress Keyy Two Factor Authentication (like Clef) plugin <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover vulnerability
WBase de données des vulnérabilités WordPress Avis de sécurité HK WPBakery Cross Site Scripting (CVE202511161)octobre 15, 2025 Plugin WordPress WPBakery Page Builder <= 8.6.1 - Vulnérabilité de Cross-Site Scripting stockée via le shortcode vc_custom_heading
WBase de données des vulnérabilités WordPress Hong Kong Security Alert DocoDoco Upload Flaw(CVE202510754)octobre 15, 2025 WordPress DocoDoco Store Locator plugin <= 1.0.1 - Authenticated (Editor+) Arbitrary File Upload vulnerability
WBase de données des vulnérabilités WordPress Civic Security Advisory Theme Importer CSRF Risk(CVE202510312)octobre 15, 2025 WordPress Theme Importer plugin <= 1.0 - Cross-Site Request Forgery vulnerability
WBase de données des vulnérabilités WordPress HK NGO Warning SSRF in Pz LinkCard(CVE20258594)octobre 15, 2025 WordPress Pz-LinkCard plugin < 2.5.7 - Contributor+ SSRF vulnerability
WBase de données des vulnérabilités WordPress Hong Kong Security Alert Insecure Image Access(CVE202511176)octobre 15, 2025 WordPress Quick Featured Images plugin <= 13.7.2 - Insecure Direct Object Reference to Image Manipulation vulnerability
WBase de données des vulnérabilités WordPress Security Notice OwnID Authentication Bypass(CVE202510294)octobre 15, 2025 WordPress OwnID Passwordless Login plugin <= 1.3.4 - Authentication Bypass vulnerability