WWordPress 漏洞数据库 Community Security Alert WordPress Employee Spotlight XSS(CVE202558915)9 月 23, 2025 WordPress Employee Spotlight plugin <= 5.1.0 - Cross Site Scripting (XSS) vulnerability
WWordPress 漏洞数据库 Community Security Alert osTicket Bridge CSRF XSS(CVE20259882)9 月 20, 2025 WordPress osTicket WP Bridge plugin <= 1.9.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability
WWordPress 漏洞数据库 Community Security Advisory StoreEngine File Upload Flaw(CVE20259216)9 月 17, 2025 WordPress StoreEngine plugin <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File Upload vulnerability
WWordPress 漏洞数据库 Hong Kong Security Alert StoreEngine Download Vulnerability(CVE20259215)9 月 17, 2025 WordPress StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File Download vulnerability
WWordPress 漏洞数据库 Community Alert WordPress Plugin Directory Deletion(CVE202510188)9 月 17, 2025 WordPress The Hack Repair Guy's Plugin Archiver plugin <= 2.0.4 - Cross-Site Request Forgery to Arbitrary Directory Deletion in /wp-content vulnerability
WWordPress 漏洞数据库 社区安全警报 Productive Style 插件 XSS(CVE20258394)2025年9月16日 WordPress Productive Style 插件 <= 1.1.23 - 认证 (贡献者+) 通过 display_productive_breadcrumb 短代码漏洞存储的跨站脚本攻击
WWordPress 漏洞数据库 事件日历数据泄露的安全警报(CVE20259808)2025年9月16日 WordPress The Events Calendar 插件 <= 6.15.2 - 缺少对未认证密码保护信息泄露的授权漏洞
WWordPress 漏洞数据库 Community Advisory Mailgun Plugin Data Exposure(CVE202559003)2025 年 9 月 14 日 WordPress WP Mailgun SMTP Plugin <= 1.0.7 - Sensitive Data Exposure Vulnerability
WWordPress 漏洞数据库 Security Advisory Cloriato Lite Data Exposure(CVE202559003)2025 年 9 月 14 日 WordPress Cloriato Lite Theme <= 1.7.2 - Sensitive Data Exposure Vulnerability