WP Security
WWordPress Vulnerability Database

Hong Kong Security Notice Missing Plugin Authorization(CVE202510746)

  • October 4, 2025
WordPress Integrate Dynamics 365 CRM plugin <= 1.0.9 - Missing Authorization vulnerability
Read More
WWordPress Vulnerability Database

Security Advisory Restrict User Registration CSRF(CVE20259892)

  • October 3, 2025
WordPress Restrict User Registration plugin <= 1.0.1 - Cross-Site Request Forgery to Settings Update vulnerability
Read More
WWordPress Vulnerability Database

ContentMX Plugin CSRF Community Advisory(CVE20259889)

  • October 3, 2025
WordPress ContentMX Content Publisher plugin <= 1.0.6 - Cross-Site Request Forgery vulnerability
Read More
WWordPress Vulnerability Database

Community Security Alert Mobile Redirect XSS Risk(CVE20259884)

  • October 3, 2025
WordPress Mobile Site Redirect plugin <= 1.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong Security Alert JoomSport Vulnerability(CVE20257721)

  • October 3, 2025
WordPress JoomSport plugin <= 5.7.3 - Unauthenticated Directory Traversal to Local File Inclusion vulnerability
Read More
WWordPress Vulnerability Database

Community Alert Notification Bar CSRF Vulnerability(CVE20259895)

  • October 3, 2025
WordPress Notification Bar plugin <= 2.2 - Cross-Site Request Forgery vulnerability
Read More
WWordPress Vulnerability Database

Community Alert Meks Easy Maps XSS Vulnerability(CVE20259206)

  • October 3, 2025
WordPress Meks Easy Maps plugin <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong Cybersecurity Alert WordPress Gallery Injection(CVE20259199)

  • October 3, 2025
WordPress Woo superb slideshow transition gallery with random effect plugin <= 9.1 - Authenticated (Contributor+) SQL Injection vulnerability
Read More
WWordPress Vulnerability Database

Community Security Notice Authenticated Contributor SQL Injection(CVE20259198)

  • October 3, 2025
WordPress Wp cycle text announcement plugin <= 8.1 - Authenticated (Contributor+) SQL Injection vulnerability
Read More
WWordPress Vulnerability Database

Community Advisory Flexi Plugin Stored XSS(CVE20259129)

  • October 3, 2025
WordPress Flexi plugin <= 4.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via flexi-form-tag Shortcode vulnerability
Read More
WP Security
© 2025 WP-Security.org Disclaimer: WP-Security.org is an independent, non-profit NGO community committed to sharing WordPress security news and information. We are not affiliated with WordPress, its parent company, or any related entities. All trademarks are the property of their respective owners.

hi there 👋 Sign up to receive awesome WP-Security Alert and update in your inbox, every week.

We don’t spam! Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

Review My Order

0

Subtotal

Taxes & shipping calculated at checkout

Checkout

 
0