WWordPress Vulnerability Database Hong Kong Security Advisory Jobmonster Authentication Bypass(CVE20255397)November 1, 2025 WordPress Jobmonster theme <= 4.8.1 - Authentication Bypass vulnerability
WWordPress Vulnerability Database Protect Hong Kong Sites From ERI Exploit(CVE202512041)November 1, 2025 WordPress ERI File Library plugin <= 1.1.0 - Missing Authorization to Unauthenticated Protected File Download vulnerability
WWordPress Vulnerability Database Community Security Advisory Unauthenticated Log Poisoning(CVE202511627)October 31, 2025 WordPress Site Checkup AI Troubleshooting with Wizard and Tips for Each Issue plugin <= 1.47 - Unauthenticated Log File Poisoning vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert Authenticated File Deletion(CVE20257846)October 31, 2025 WordPress User Extra Fields plugin <= 16.7 - Authenticated (Subscriber+) Arbitrary File Deletion via save_fields Function vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert WooCommerce Data Exposure(CVE20237320)October 29, 2025 WordPress WooCommerce plugin <= 7.8.2 - Sensitive Information Exposure vulnerability
WWordPress Vulnerability Database Community Alert CSRF Risk in WordPress Sync(CVE202511976)October 28, 2025 WordPress FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin <= 1.1.23.0 - Cross-Site Request Forgery to Sync Rule Creation vulnerability
WWordPress Vulnerability Database Hong Kong Alert Listeo Stored XSS Threat(CVE20258413)October 28, 2025 WordPress Listeo plugin <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via soundcloud Shortcode vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert GenerateBlocks Options Exposure(CVE202511879)October 25, 2025 WordPress GenerateBlocks plugin <= 2.1.1 - Improper Authorization to Authenticated (Contributor+) Arbitrary Options Disclosure vulnerability
WWordPress Vulnerability Database Community Advisory PixelYourSite Plugin LFI Risk(CVE202510723)October 25, 2025 WordPress PixelYourSite plugin < 11.1.2 - Admin+ LFI vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert ZoloBlocks Popup Flaw(CVE202512134)October 23, 2025 WordPress ZoloBlocks plugin <= 2.3.11 - Missing Authorization to Unauthenticated Popup Enable/Disable vulnerability