WP Security

Browsing Tag

WordPress Security

447 posts
WWordPress Vulnerability Database

Security Advisory Booster for WooCommerce File Upload(CVE202413342)

  • August 30, 2025
WordPress Booster for WooCommerce plugin <= 7.2.4 - Unauthenticated Double Extension Arbitrary File Upload vulnerability
WWordPress Vulnerability Database

Hong Kong Security Advisory Slider Revolution Vulnerability(CVE20259217)

  • August 29, 2025
WordPress Slider Revolution plugin <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images' vulnerability
WWordPress Vulnerability Database

Hong Kong Security Alert iATS SQL Injection(CVE20259441)

  • August 29, 2025
WordPress iATS Online Forms plugin <= 1.2 - Authenticated (Contributor+) SQL Injection via order Parameter vulnerability
WWordPress Vulnerability Database

Security Alert Related Posts Lite CSRF Vulnerability(CVE20259618)

  • August 29, 2025
WordPress Related Posts Lite plugin <= 1.12 - Cross-Site Request Forgery vulnerability
WWordPress Vulnerability Database

CSRF Vulnerability in Ultimate Tag Warrior Importer(CVE20259374)

  • August 28, 2025
WordPress Ultimate Tag Warrior Importer plugin <= 0.2 - Cross-Site Request Forgery vulnerability
WWordPress Vulnerability Database

Security Alert LWSCache Authorization Bypass Risk(CVE20258147)

  • August 28, 2025
WordPress LWSCache plugin <= 2.8.5 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation via lwscache_activatePlugin Function vulnerability
WWordPress Vulnerability Database

Security Advisory List Subpages Plugin Stored XSS(CVE20258290)

  • August 28, 2025
WordPress List Subpages plugin <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter vulnerability
WWordPress Vulnerability Database

Security Advisory OSM Map Widget Stored XSS(CVE20258619)

  • August 28, 2025
WordPress OSM Map Widget for Elementor plugin <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button URL vulnerability
WWordPress Vulnerability Database

Community Advisory Stored XSS in Events Addon(CVE20258150)

  • August 28, 2025
WordPress Events Addon for Elementor plugin <= 2.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typewriter and Countdown Widgets vulnerability
WWordPress Vulnerability Database

Community Advisory RingCentral Two Factor Bypass(CVE20257955)

  • August 28, 2025
WordPress RingCentral Communications plugin 1.5-1.6.8 - Missing Server‑Side Verification to Authentication Bypass via ringcentral_admin_login_2fa_verify Function
WP Security
© 2025 WP-Security.org Disclaimer: WP-Security.org is an independent, non-profit NGO community committed to sharing WordPress security news and information. We are not affiliated with WordPress, its parent company, or any related entities. All trademarks are the property of their respective owners.

Review My Order

0

Subtotal

Taxes & shipping calculated at checkout

Checkout

 
0