A vulnerability was found in Foxtool All-in-One Plugin up to 2.5.2 on WordPress. It has been rated as problematic. This affects the function foxtool_login_google of the component Google OAuth Connection. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-13408. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability identified as problematic has been detected in Simple Nivo Slider Plugin up to 0.5.6 on WordPress. This issue affects some unknown processing of the component Shortcode Handler. This manipulation of the argument ID causes cross site scripting.
This vulnerability is handled as CVE-2025-13889. The attack can be initiated remotely. There is not any exploit available.
A vulnerability classified as problematic has been found in WPGancio Plugin up to 1.12 on WordPress. This affects the function gancio-event of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2025-13904. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability, which was classified as problematic, has been found in Easy Map Creator Plugin up to 3.0.2 on WordPress. Affected is an unknown function of the component Shortcode Handler. This manipulation of the argument width causes cross site scripting.
This vulnerability is tracked as CVE-2025-13846. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in BUKAZU Search Widget Plugin up to 3.3.2 on WordPress. It has been classified as problematic. This vulnerability affects the function bukazu_search of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2025-13840. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in Data Visualizer Plugin up to 1.1 on WordPress. It has been declared as problematic. This issue affects the function visualize of the component Shortcode Handler. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2025-13961. The attack can be launched remotely. No exploit exists.
A vulnerability categorized as problematic has been discovered in WP Flot Plugin up to 0.2.2 on WordPress. The affected element is the function linechart of the component Shortcode Handler. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-13906. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in VigLink SpotLight by ShortCode Plugin up to 1.0.a on WordPress. This affects the function spotlight of the component Shortcode Handler. Performing manipulation of the argument float results in cross site scripting.
This vulnerability is identified as CVE-2025-13843. The attack can be initiated remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, was found in Zenost Shortcodes Plugin up to 1.0 on WordPress. This vulnerability affects unknown code of the component Shortcode Handler. Executing manipulation of the argument link/target can lead to cross site scripting.
This vulnerability is tracked as CVE-2025-13885. The attack can be launched remotely. No exploit exists.