WWordPress Vulnerability Database Community Security Alert Demo Import Kit(CVE202510051)October 15, 2025 WordPress Demo Import Kit plugin <= 1.1.0 - Authenticated (Admin+) Arbitrary File Upload vulnerability
WWordPress Vulnerability Database Civic Cybersecurity Alert onOffice SQL Injection(CVE202510045)October 15, 2025 WordPress onOffice for WP-Websites plugin <= 5.7 - Authenticated (Editor+) SQL Injection vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory Shortcode Button XSS(CVE202510194)October 15, 2025 WordPress Shortcode Button plugin <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory Theme Importer CSRF(CVE202510312)October 15, 2025 WordPress Theme Importer plugin <= 1.0 - Cross-Site Request Forgery vulnerability
WWordPress Vulnerability Database Community Alert Digiseller Plugin Authenticated XSS(CVE202510141)October 15, 2025 WordPress Digiseller plugin <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert SSO Data Exposure(CVE202510648)October 15, 2025 WordPress Login with YourMembership - YM SSO Login plugin <= 1.1.7 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'moym_display_test_attributes' vulnerability
WWordPress Vulnerability Database Hong Kong Security Notice FunKItools CSRF Vulnerability(CVE202510301)October 15, 2025 WordPress FunKItools plugin <= 1.0.2 - Cross-Site Request Forgery to Settings Update vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory WordPress Image Exposure(CVE202511176)October 15, 2025 WordPress Quick Featured Images plugin <= 13.7.2 - Insecure Direct Object Reference to Image Manipulation vulnerability
WWordPress Vulnerability Database Community Security Alert External Login SQL Injection(CVE202511177)October 15, 2025 WordPress External Login plugin <= 1.11.2 - Unauthenticated SQL Injection via log vulnerability
WWordPress Vulnerability Database HK Security Advisory Social Login Stored XSS(CVE202510140)October 15, 2025 WordPress Quick Social Login plugin <= 1.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability