WP Security
WWordPress Vulnerability Database

Hong Kong Security Alert JoomSport Vulnerability(CVE20257721)

  • October 3, 2025
WordPress JoomSport plugin <= 5.7.3 - Unauthenticated Directory Traversal to Local File Inclusion vulnerability
Read More
WWordPress Vulnerability Database

Community Alert Notification Bar CSRF Vulnerability(CVE20259895)

  • October 3, 2025
WordPress Notification Bar plugin <= 2.2 - Cross-Site Request Forgery vulnerability
Read More
WWordPress Vulnerability Database

Community Alert Meks Easy Maps XSS Vulnerability(CVE20259206)

  • October 3, 2025
WordPress Meks Easy Maps plugin <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong Cybersecurity Alert WordPress Gallery Injection(CVE20259199)

  • October 3, 2025
WordPress Woo superb slideshow transition gallery with random effect plugin <= 9.1 - Authenticated (Contributor+) SQL Injection vulnerability
Read More
WWordPress Vulnerability Database

Community Security Notice Authenticated Contributor SQL Injection(CVE20259198)

  • October 3, 2025
WordPress Wp cycle text announcement plugin <= 8.1 - Authenticated (Contributor+) SQL Injection vulnerability
Read More
WWordPress Vulnerability Database

Community Advisory Flexi Plugin Stored XSS(CVE20259129)

  • October 3, 2025
WordPress Flexi plugin <= 4.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via flexi-form-tag Shortcode vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong Security Advisory Video Carousel XSS(CVE20259372)

  • October 3, 2025
WordPress Ultimate Multi Design Video Carousel plugin <= 1.4 - Authenticated (Editor+) Stored Cross-Site Scripting vulnerability
Read More
WWordPress Vulnerability Database

Community Security Notice Mobile Site Redirect Vulnerability(CVE20259884)

  • October 3, 2025
WordPress Mobile Site Redirect plugin <= 1.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability
Read More
WWordPress Vulnerability Database

HK NGO alerts Comment Info Detector vulnerability(CVE202510311)

  • October 3, 2025
WordPress Comment Info Detector plugin <= 1.0.5 - Cross-Site Request Forgery to Settings Update vulnerability
Read More
WWordPress Vulnerability Database

Hong Kong Security Alert WordPress Stored XSS(CVE20259077)

  • October 3, 2025
WordPress Ultra Addons Lite for Elementor plugin <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Field vulnerability
Read More
WP Security
© 2025 WP-Security.org Disclaimer: WP-Security.org is an independent, non-profit NGO community committed to sharing WordPress security news and information. We are not affiliated with WordPress, its parent company, or any related entities. All trademarks are the property of their respective owners.

hi there 👋 Sign up to receive awesome WP-Security Alert and update in your inbox, every week.

We don’t spam! Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

Review My Order

0

Subtotal

Taxes & shipping calculated at checkout

Checkout

 
0
English
Chinese (Hong Kong) Chinese (China) Spanish Hindi French