WP Security
WWordPress Vulnerability Database

HK Security Alert Instant Breaking News CSRF(CVE202558217)

  • August 27, 2025
WordPress Instant Breaking News Plugin <= 1.0 - Cross Site Request Forgery (CSRF) Vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong NGO Alert PHP Object Injection(CVE202558218)

  • August 27, 2025
WordPress Small Package Quotes – USPS Edition Plugin <= 1.3.9 - PHP Object Injection Vulnerability
Read More
WWordPress Vulnerability Database

HK Security Alert Xpro Elementor XSS(CVE202558195)

  • August 27, 2025
WordPress Xpro Elementor Addons Plugin <= 1.4.17 - Cross Site Scripting (XSS) Vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong NGO Warns Trafft Booking XSS(CVE202558213)

  • August 27, 2025
WordPress Booking System Trafft Plugin <= 1.0.14 - Cross Site Scripting (XSS) Vulnerability
Read More
WWordPress Vulnerability Database

AfterShip Plugin Broken Access Control Advisory(CVE202558201)

  • August 27, 2025
WordPress AfterShip Tracking Plugin <= 1.17.17 - Broken Access Control Vulnerability
Read More
WWordPress Vulnerability Database

Community Notice CSRF in Simple Page Access(CVE202558202)

  • August 27, 2025
WordPress Simple Page Access Restriction Plugin <= 1.0.32 - Cross Site Request Forgery (CSRF) Vulnerability
Read More
WWordPress Vulnerability Database

Security Advisory WpEvently PHP Object Injection(CVE202554742)

  • August 27, 2025
WordPress WpEvently Plugin <= 4.4.8 - PHP Object Injection Vulnerability
Read More
WWordPress Vulnerability Database

Public Advisory Printeers Print Ship Directory Traversal(CVE202548081)

  • August 27, 2025
WordPress Printeers Print & Ship plugin <= 1.17.0 - Directory Traversal vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong Security NGO WordPress Import XSS(CVE20258490)

  • August 26, 2025
WordPress All-in-One WP Migration and Backup plugin <= 7.97 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import vulnerability
Read More
WWordPress Vulnerability Database

Stored XSS in Lazy Load Videos Plugin(CVE20257732)

  • August 26, 2025
WordPress Lazy Load for Videos plugin <= 2.18.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via data-video-title and href Attributes vulnerability
Read More
WP Security
© 2025 WP-Security.org Disclaimer: WP-Security.org is an independent, non-profit NGO community committed to sharing WordPress security news and information. We are not affiliated with WordPress, its parent company, or any related entities. All trademarks are the property of their respective owners.

hi there 👋 Sign up to receive awesome WP-Security Alert and update in your inbox, every week.

We don’t spam! Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

Review My Order

0

Subtotal

Taxes & shipping calculated at checkout

Checkout

 
0