WWordPress Vulnerability Database HK Security Alerts Elementor Image Import Flaw(CVE20258081)August 11, 2025 WordPress Elementor plugin <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import vulnerability
WWordPress Vulnerability Database Hong Kong security NGO flags CBX CSRF(CVE20257965)August 11, 2025 WordPress CBX Restaurant Booking plugin <= 1.2.1 - Plugin Reset via CSRF vulnerability
WWordPress Vulnerability Database Hong Kong WordPress The7 Stored XSS Alert(CVE20257726)August 11, 2025 WordPress The7 plugin <= 12.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via title and data-dt-img-description Attributes vulnerability
WWordPress Vulnerability Database Hong Kong Security Unauthenticated SQL Injection CleverReach(CVE20257036)August 11, 2025 WordPress CleverReach WP plugin <= 1.5.20 - Unauthenticated SQL Injection via title Parameter vulnerability
WWordPress Vulnerability Database Hong Kong Security NGO Warns FundEngine LFI(CVE202548302)August 10, 2025 WordPress FundEngine Plugin <= 1.7.4 - Local File Inclusion Vulnerability
WWordPress Vulnerability Database Hong Kong Security Alerts GravityWP LFI(CVE202549271)August 10, 2025 WordPress GravityWP - Merge Tags <= 1.4.4 - Local File Inclusion Vulnerability
WWordPress Vulnerability Database Urgent MapSVG WordPress SQL Injection Risk(CVE202554669)August 10, 2025 WordPress MapSVG Plugin < 8.7.4 - SQL Injection Vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory WordPress IDonatePro Flaw(CVE202530639)August 10, 2025 WordPress IDonatePro Plugin <= 2.1.9 - Broken Access Control Vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory Eventin Email Change(CVE20254796)August 8, 2025 WordPress Eventin plugin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory OpenStreetMap WordPress XSS(CVE20256572)August 8, 2025 WordPress OpenStreetMap for Gutenberg and WPBakery Page Builder plugin <= 1.2.0 - Contributor+ Stored XSS vulnerability