WWordPress Vulnerability Database Security Alert WordPress Zip Attachment Exposure(CVE202511701)October 15, 2025 WordPress Zip Attachments plugin <= 1.6 - Missing Authorization to Unauthenticated Private And Password-Protected Posts Attachment Disclosure vulnerability Read More
WWordPress Vulnerability Database Public Advisory Theme Importer CSRF Vulnerability(CVE202510312)October 15, 2025 WordPress Theme Importer plugin <= 1.0 - Cross-Site Request Forgery vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Alert Lisfinity Privilege Escalation(CVE20256042)October 15, 2025 WordPress Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin <= 1.4.0 - Unauthenticated Privilege Escalation to Editor vulnerability Read More
WWordPress Vulnerability Database Oceanpayment Plugin Permits Unauthenticated Order Status Changes(CVE202511728)October 15, 2025 WordPress Oceanpayment CreditCard Gateway plugin <= 6.0 - Missing Authentication to Unauthenticated Order Status Update vulnerability Read More
WWordPress Vulnerability Database Security Advisory Dynamically Display Posts SQL Injection(CVE202511501)October 15, 2025 WordPress Dynamically Display Posts plugin <= 1.1 - Unauthenticated SQL Injection vulnerability Read More
WWordPress Vulnerability Database Community Advisory Shortcode Button Stored XSS(CVE202510194)October 15, 2025 WordPress Shortcode Button plugin <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability Read More
WWordPress Vulnerability Database Community Security Alert Demo Import Kit Vulnerability(CVE202510051)October 15, 2025 WordPress Demo Import Kit plugin <= 1.1.0 - Authenticated (Admin+) Arbitrary File Upload vulnerability Read More
WWordPress Vulnerability Database Community Alert NEX Forms SQL Injection(CVE202510185)October 11, 2025 WordPress NEX-Forms – Ultimate Forms Plugin for WordPress plugin <= 9.1.6 - Authenticated (Admin+) SQL Injection vulnerability Read More
WWordPress Vulnerability Database Community Advisory Ovatheme Events Arbitrary Upload(CVE20256553)October 11, 2025 WordPress Ovatheme Events Manager plugin <= 1.8.5 - Unauthenticated Arbitrary File Upload vulnerability Read More
WWordPress Vulnerability Database Security Advisory Everest Backup Exposes User Data(CVE202511380)October 11, 2025 WordPress Everest Backup plugin <= 2.3.5 - Missing Authorization to Unauthenticated Information Exposure vulnerability Read More