Aggregator
CVE-2025-52819 | pakkemx Pakke Envíos Plugin up to 1.0.2 on WordPress sql injection
7 months 1 week ago
A vulnerability was found in pakkemx Pakke Envíos Plugin up to 1.0.2 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2025-52819. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-49884 | alexvtn Internal Linking of Related Contents Plugin up to 1.1.8 on WordPress authorization
7 months 1 week ago
A vulnerability has been found in alexvtn Internal Linking of Related Contents Plugin up to 1.1.8 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2025-49884. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-40776 | ISC BIND 9 up to 9.16.50-S1/9.18.37-S1/9.20.9/9.20.10-S1 ECS Options acceptance of extraneous untrusted data with trusted data
7 months 1 week ago
A vulnerability, which was classified as problematic, has been found in ISC BIND 9 up to 9.16.50-S1/9.18.37-S1/9.20.9/9.20.10-S1. Affected by this issue is some unknown functionality of the component ECS Options Handler. The manipulation leads to acceptance of extraneous untrusted data with trusted data.
This vulnerability is handled as CVE-2025-40776. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-52714 | shinetheme Traveler Plugin up to 3.2.1 on WordPress sql injection
7 months 1 week ago
A vulnerability, which was classified as critical, was found in shinetheme Traveler Plugin up to 3.2.1 on WordPress. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-52714. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-34300 | Sawtooth Lighthouse Studio up to 9.16.13 ciwweb.pl special elements used in a template engine
7 months 1 week ago
A vulnerability classified as critical was found in Sawtooth Lighthouse Studio up to 9.16.13. Affected by this vulnerability is an unknown functionality of the file ciwweb.pl. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is known as CVE-2025-34300. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-40923 | MIYAGAWA Plack::Middleware::Session up to 0.34 on Perl rand generation of predictable numbers or identifiers
7 months 1 week ago
A vulnerability classified as problematic has been found in MIYAGAWA Plack::Middleware::Session up to 0.34 on Perl. Affected is the function rand. The manipulation leads to generation of predictable numbers or identifiers.
This vulnerability is traded as CVE-2025-40923. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-49876 | Metagauss ProfileGrid Plugin up to 5.9.5.2 on WordPress sql injection
7 months 1 week ago
A vulnerability was found in Metagauss ProfileGrid Plugin up to 5.9.5.2 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2025-49876. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-48294 | Kerfred FG Drupal to WordPress Plugin up to 3.90.0 on WordPress server-side request forgery
7 months 1 week ago
A vulnerability was found in Kerfred FG Drupal to WordPress Plugin up to 3.90.0 on WordPress. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2025-48294. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Qilin
7 months 1 week ago
You must login to view this content
cohenido
CVE-2025-47554 | QuanticaLabs CSS3 Compare Pricing Tables Plugin up to 11.6 on WordPress cross site scripting
7 months 1 week ago
A vulnerability was found in QuanticaLabs CSS3 Compare Pricing Tables Plugin up to 11.6 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-47554. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Qilin
7 months 1 week ago
You must login to view this content
cohenido
CVE-2025-46500 | ValvePress Wordpress Auto Spinner Plugin up to 3.25.0 on WordPress cross site scripting
7 months 1 week ago
A vulnerability was found in ValvePress Wordpress Auto Spinner Plugin up to 3.25.0 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-46500. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-31427 | designthemes Invico Plugin up to 1.9 on WordPress cross site scripting
7 months 1 week ago
A vulnerability has been found in designthemes Invico Plugin up to 1.9 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-31427. The attack can be launched remotely. There is no exploit available.
vuldb.com
Keeper Security Adds Support for MCP to Secrets Management Platform
7 months 1 week ago
Keeper Security is making its secrets management platform more accessible to artificial intelligence (AI) agents by adding support for the Model Context Protocol (MCP).
The post Keeper Security Adds Support for MCP to Secrets Management Platform appeared first on Security Boulevard.
Michael Vizard
CVE-2025-31072 | designthemes Ofiz Plugin up to 2.0 on WordPress cross site scripting
7 months 1 week ago
A vulnerability, which was classified as problematic, was found in designthemes Ofiz Plugin up to 2.0 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-31072. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-31055 | vergatheme Electrician Plugin up to 1.0 on WordPress cross site scripting
7 months 1 week ago
A vulnerability, which was classified as problematic, has been found in vergatheme Electrician Plugin up to 1.0 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-31055. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-30936 | Torod Plugin up to 1.9 on WordPress sql injection
7 months 1 week ago
A vulnerability classified as critical was found in Torod Plugin up to 1.9 on WordPress. This vulnerability affects unknown code. The manipulation leads to sql injection.
This vulnerability was named CVE-2025-30936. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-29000 | August Infotech Multi-language Responsive Contact Form Plugin up to 2.8 on WordPress authorization
7 months 1 week ago
A vulnerability classified as problematic has been found in August Infotech Multi-language Responsive Contact Form Plugin up to 2.8 on WordPress. This affects an unknown part. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2025-29000. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-28982 | ThimPress WP Pipes Plugin up to 1.4.3 on WordPress sql injection
7 months 1 week ago
A vulnerability was found in ThimPress WP Pipes Plugin up to 1.4.3 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2025-28982. The attack may be launched remotely. There is no exploit available.
vuldb.com