WWordPress Vulnerability Database Hong Kong Security Alert Authenticated File Deletion(CVE20257846)October 31, 2025 WordPress User Extra Fields plugin <= 16.7 - Authenticated (Subscriber+) Arbitrary File Deletion via save_fields Function vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Alert WooCommerce Data Exposure(CVE20237320)October 29, 2025 WordPress WooCommerce plugin <= 7.8.2 - Sensitive Information Exposure vulnerability Read More
WWordPress Vulnerability Database Community Alert CSRF Risk in WordPress Sync(CVE202511976)October 28, 2025 WordPress FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin <= 1.1.23.0 - Cross-Site Request Forgery to Sync Rule Creation vulnerability Read More
WWordPress Vulnerability Database Hong Kong Alert Listeo Stored XSS Threat(CVE20258413)October 28, 2025 WordPress Listeo plugin <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via soundcloud Shortcode vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Alert GenerateBlocks Options Exposure(CVE202511879)October 25, 2025 WordPress GenerateBlocks plugin <= 2.1.1 - Improper Authorization to Authenticated (Contributor+) Arbitrary Options Disclosure vulnerability Read More
WWordPress Vulnerability Database Community Advisory PixelYourSite Plugin LFI Risk(CVE202510723)October 25, 2025 WordPress PixelYourSite plugin < 11.1.2 - Admin+ LFI vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Alert ZoloBlocks Popup Flaw(CVE202512134)October 23, 2025 WordPress ZoloBlocks plugin <= 2.3.11 - Missing Authorization to Unauthenticated Popup Enable/Disable vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Alert WordPress Template CSRF(CVE202512072)October 23, 2025 WordPress Disable Content Editor For Specific Template plugin <= 2.0 - Cross-Site Request Forgery to Template Configuration Update vulnerability Read More
WWordPress Vulnerability Database Community Alert WordPress RapidResult SQL Injection(CVE202510748)October 23, 2025 WordPress RapidResult plugin <= 1.2 - Authenticated (Contributor+) SQL Injection vulnerability Read More
WWordPress Vulnerability Database Security Advisory Arbitrary Order Refund Vulnerability(CVE202510570)October 22, 2025 WordPress Flexible Refund and Return Order for WooCommerce plugin <= 1.0.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Refund vulnerability Read More