WWordPress Vulnerability Database Community Advisory Vibes Plugin SQL Injection Vulnerability(CVE20259172)August 26, 2025 WordPress Vibes plugin <= 2.2.0 - Unauthenticated SQL Injection via `resource` Parameter vulnerability
WWordPress Vulnerability Database Community Security Alert CSRF in WordPress Plugin(CVE202548303)August 25, 2025 WordPress Post Type Converter plugin <= 0.6 - Cross Site Request Forgery (CSRF) vulnerability
WWordPress Vulnerability Database Duoshuo Comment Box CSRF Security Alert(CVE202548318)August 25, 2025 WordPress 多说社会化评论框 plugin <= 1.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
WWordPress Vulnerability Database Community Alert Baidu Share Button Stored XSS(CVE202548320)August 25, 2025 WordPress 百度分享按钮 plugin <= 1.0.6 - CSRF to Stored XSS vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory Mesa Widget XSS(CVE202548319)August 25, 2025 WordPress Mesa Mesa Reservation Widget plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability
WWordPress Vulnerability Database Hong Kong Advisory CSRF Enables Stored XSS(CVE202548321)August 25, 2025 WordPress Ultimate twitter profile widget plugin <= 1.0 - CSRF to Stored XSS vulnerability
WWordPress Vulnerability Database Community Alert Bravis Plugin Account Takeover(CVE20255060)August 22, 2025 Plugin Name Bravis User Type of Vulnerability Account takeover vulnerability CVE Number CVE-2025-5060 Urgency High CVE Publish Date…
WWordPress Vulnerability Database HK NGO Alert Social Login Authentication Bypass(CVE20255821)August 22, 2025 WordPress Case Theme User plugin <= 1.0.3 - Authentication Bypass via Social Login vulnerability
WWordPress Vulnerability Database Hong Kong Security Advisory Ogulo 360 XSS(CVE20259131)August 22, 2025 Plugin Name Ogulo – 360° Tour Type of Vulnerability Authenticated Stored XSS CVE Number CVE-2025-9131 Urgency Low CVE…
WWordPress Vulnerability Database Hong Kong Security Advisory Ni WooCommerce Vulnerability(CVE20257827)August 22, 2025 WordPress Ni WooCommerce Customer Product Report plugin <= 1.2.4 - Missing Authorization to Authenticated (Subscriber+) Settings Update vulnerability