WP Security

Browsing Tag

WordPress Security

399 posts
WWordPress Vulnerability Database

Hong Kong Security Notice wpmpdf XSS Risk(CVE202560040)

  • September 26, 2025
WordPress wp-mpdf Plugin <= 3.9.1 - Cross Site Scripting (XSS) Vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert Vehica CSRF Vulnerability(CVE202560117)

  • September 26, 2025
WordPress Vehica Core Plugin <= 1.0.100 - Cross Site Request Forgery (CSRF) Vulnerability
WWordPress Vulnerability Database

Community Alert XSS in Support Ticket Plugin(CVE202560157)

  • September 26, 2025
WordPress WP Ticket Customer Service Software & Support Ticket System Plugin <= 6.0.2 - Cross Site Scripting (XSS) Vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert Mega Elements XSS(CVE20258200)

  • September 26, 2025
WordPress Mega Elements plugin <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert OAuth SSO Vulnerability(CVE202510752)

  • September 26, 2025
WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 6.26.12 - Cross-Site Request Forgery vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert Tiktok Feed XSS(CVE20258906)

  • September 25, 2025
WordPress Widgets for Tiktok Feed plugin <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database

Themify Builder Stored Cross Site Scripting Vulnerability(CVE20259353)

  • September 24, 2025
WordPress Themify Builder plugin <= 7.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database

Community Security Alert WordPress Employee Spotlight XSS(CVE202558915)

  • September 23, 2025
WordPress Employee Spotlight plugin <= 5.1.0 - Cross Site Scripting (XSS) vulnerability
WWordPress Vulnerability Database

Community Security Alert osTicket Bridge CSRF XSS(CVE20259882)

  • September 20, 2025
WordPress osTicket WP Bridge plugin <= 1.9.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database

Community Security Advisory StoreEngine File Upload Flaw(CVE20259216)

  • September 17, 2025
WordPress StoreEngine plugin <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File Upload vulnerability
WP Security
© 2025 WP-Security.org Disclaimer: WP-Security.org is an independent, non-profit NGO community committed to sharing WordPress security news and information. We are not affiliated with WordPress, its parent company, or any related entities. All trademarks are the property of their respective owners.

Review My Order

0

Subtotal

Taxes & shipping calculated at checkout

Checkout

 
0