WP Security
WWordPress Vulnerability Database

Hong Kong Security Alert WordPress Unauthenticated Exposure(CVE20254390)

  • August 11, 2025
Plugin Name WP Private Content Plus Type of Vulnerability Unauthenticated Information Disclosure CVE Number CVE-2025-4390 Urgency Low CVE…
Read More
WWordPress Vulnerability Database

Hong Kong Security Advisory Stored XSS Slider(CVE20258690)

  • August 11, 2025
WordPress Simple Responsive Slider plugin <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong Security Advisory WordPress Elementor XSS(CVE20258874)

  • August 11, 2025
WordPress Master Addons for Elementor plugin <= 2.0.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via fancyBox vulnerability
Read More
WWordPress Vulnerability Database

HK Security Alerts WordPress RT Builder XSS(CVE20258462)

  • August 11, 2025
WordPress RT Easy Builder plugin <= 2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong Security Warns WordPress Mosaic Generator XSS(CVE20258621)

  • August 11, 2025
WordPress Mosaic Generator plugin <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'c' Parameter vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong Security Avatar Migration Authorization Flaw(CVE20258482)

  • August 11, 2025
WordPress Simple Local Avatars plugin <= 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Avatar Migration vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong Security WordPress Stock Quotes XSS(CVE20258688)

  • August 11, 2025
WordPress Inline Stock Quotes plugin <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via stock Shortcode vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong Security NGO warns WordPress XSS(CVE20258685)

  • August 11, 2025
WordPress Wp chart generator plugin <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpchart Shortcode vulnerability
Read More
WWordPress Vulnerability Database

GMap Venturit Stored XSS Alert for HK(CVE20258568)

  • August 11, 2025
WordPress GMap - Venturit plugin <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'h' Parameter vulnerability
Read More
WWordPress Vulnerability Database

Authenticated CSV Injection in AnWP Football Leagues(CVE20258767)

  • August 11, 2025
WordPress AnWP Football Leagues plugin <= 0.16.17 - Authenticated (Administrator+) CSV Injection vulnerability
Read More
WP Security
© 2025 WP-Security.org Disclaimer: WP-Security.org is an independent, non-profit NGO community committed to sharing WordPress security news and information. We are not affiliated with WordPress, its parent company, or any related entities. All trademarks are the property of their respective owners.

hi there 👋 Sign up to receive awesome WP-Security Alert and update in your inbox, every week.

We don’t spam! Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

Review My Order

0

Subtotal

Taxes & shipping calculated at checkout

Checkout

 
0