WWordPress Vulnerability Database Hong Kong Security Advisory WordPress Soledad Stored XSS(CVE20258143)August 16, 2025 WordPress Soledad plugin <= 8.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pcsml_smartlists_h' vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security NGO Warns Unauthenticated Shortcode(CVE20258105)August 16, 2025 WordPress Soledad plugin <= 8.6.7 - Unauthenticated Arbitrary Shortcode Execution vulnerability Read More
WWordPress Vulnerability Database Hong Kong NGO warns ProfilePress shortcode vulnerability(CVE20258878)August 16, 2025 WordPress ProfilePress plugin <= 4.16.4 - Unauthenticated Arbitrary Shortcode Execution vulnerability Read More
WWordPress Vulnerability Database HK Security NGO Warns CF7 Directory Traversal(CVE20258464)August 16, 2025 WordPress Drag and Drop Multiple File Upload for Contact Form 7 plugin <= 1.3.9.0 - Directory Traversal via `wpcf7_guest_user_id` Cookie vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security NGO Alerts WPGYM LFI(CVE20253671)August 16, 2025 WordPress WPGYM - Wordpress Gym Management System plugin <= 67.7.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update vulnerability Read More
WWordPress Vulnerability Database HK Security NGO Warns WPGYM Admin Flaw(CVE20256080)August 16, 2025 WordPress WPGYM plugin <= 67.7.0 - Missing Authorization to Admin Account Creation vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Alert WordPress Calendar XSS(CVE20258293)August 16, 2025 WordPress Intl DateTime Calendar plugin <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via date Parameter vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security NGO Warns WordPress SQLi(CVE202412612)August 16, 2025 WordPress School Management System for Wordpress plugin <= 93.2.0 - Unauthenticated SQL Injection vulnerability Read More
WWordPress Vulnerability Database Hong Kong Security Watch WordPress CSRF XSS(CVE20257668)August 16, 2025 WordPress Linux Promotional Plugin plugin <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability Read More
WWordPress Vulnerability Database Hong Kong Advisory Authenticated Anber Elementor XSS(CVE20257440)August 16, 2025 WordPress Anber Elementor Addon plugin <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Carousel button link vulnerability Read More