WWordPress Vulnerability Database Security Advisory WpEvently PHP Object Injection(CVE202554742)August 27, 2025 WordPress WpEvently Plugin <= 4.4.8 - PHP Object Injection Vulnerability
WWordPress Vulnerability Database Public Advisory Printeers Print Ship Directory Traversal(CVE202548081)August 27, 2025 WordPress Printeers Print & Ship plugin <= 1.17.0 - Directory Traversal vulnerability
WWordPress Vulnerability Database Hong Kong Security NGO WordPress Import XSS(CVE20258490)August 26, 2025 WordPress All-in-One WP Migration and Backup plugin <= 7.97 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import vulnerability
WWordPress Vulnerability Database Stored XSS in Lazy Load Videos Plugin(CVE20257732)August 26, 2025 WordPress Lazy Load for Videos plugin <= 2.18.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via data-video-title and href Attributes vulnerability
WWordPress Vulnerability Database Hong Kong Security Dokan Pro Privilege Escalation(CVE20255931)August 26, 2025 WordPress Dokan Pro plugin <= 4.0.5 - Authenticated (Vendor+) Privilege Escalation vulnerability
WWordPress Vulnerability Database Community Security Advisory SiteSEO Stored XSS(CVE20259277)August 26, 2025 WordPress SiteSEO plugin <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Broken Regex Expression vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory Shortcode Path Traversal(CVE20258562)August 26, 2025 Urgent: Directory Traversal in ‘Custom Query Shortcode’ (≤ 0.4.0) — What WordPress Site Owners Need to Know and…
WWordPress Vulnerability Database Tourfic Plugin Missing Authorization Weakens Site Security(CVE20248860)August 26, 2025 Tourfic
WWordPress Vulnerability Database Hong Kong Security Notice Event List Escalation(CVE20256366)August 26, 2025 WordPress Event List plugin <= 2.0.4 - Authenticated (Subscriber+) Privilege Escalation vulnerability
WWordPress Vulnerability Database Hong Kong Security Alert Plugin CSRF XSS(CVE20256247)August 26, 2025 WordPress WordPress Automatic plugin <= 3.118.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability