WWordPress Vulnerability Database Hong Kong NGO alerts contributors about XSS(CVE20257496)August 18, 2025 WordPress WPC Smart Compare for WooCommerce plugin <= 6.4.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Advisory FunnelKit Privilege Escalation(CVE20257654)August 18, 2025 WordPress FunnelKit plugin <= 3.11.0.2 - Privilege Escalation vulnerability Read More
WWordPress Vulnerability Database Community Advisory Real Spaces Administrator Escalation(CVE20256758)August 18, 2025 WordPress Real Spaces - WordPress Properties Directory Theme plugin <= 3.6 - Unauthenticated Privilege Escalation to Administrator via 'imic_agent_register' vulnerability Read More
WWordPress Vulnerability Database Community Alert Cloudflare Image Resizing Exploit(CVE20258723)August 18, 2025 WordPress Cloudflare Image Resizing plugin <= 1.5.6 - Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Advisory Flexible Maps XSS(CVE20258622)August 18, 2025 WordPress Flexible Maps plugin <= 1.18.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flexible Maps Shortcode vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Alert Real Spaces Escalation(CVE20258218)August 18, 2025 WordPress Real Spaces - WordPress Properties Directory Theme plugin <= 3.5 - Authenticated (Subscriber+) Privilege Escalation to Administrator via 'change_role_member' vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Alert Media Library Deletion(CVE20258357)August 18, 2025 WordPress Media Library Assistant plugin <= 3.27 - Authenticated (Author+) Limited File Deletion vulnerability Read More
WWordPress Vulnerability Database Community Alert Emmet Plugin XSS Threat(CVE202549894)August 18, 2025 WordPress WP Emmet plugin <= 0.3.4 - Cross Site Scripting (XSS) vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Notice Elizaibots XSS Vulnerability(CVE202549893)August 18, 2025 WordPress Elizaibots plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability Read More
WWordPress Vulnerability Database HK NGO warns WordPress CSRF Object Injection(CVE202549895)August 16, 2025 WordPress ServerBuddy by PluginBuddy.com plugin <= 1.0.5 - CSRF to PHP Object Injection vulnerability Read More