漏洞列表 352871
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-11164
Mavix Education <= 1.0 - Missing Authorization to Authenticated (Subscriber+) 'Creativ Demo Importer' Plugin Activation
MEDIUM 4.3 2025-12-13
creativthemes Mavix Education
CVE NVD
CVE-2025-11707
Login Lockdown & Protection <= 2.14 - IP Block Bypass
MEDIUM 5.3 2025-12-13
webfactory Login Lockdown & Protection
CVE NVD
CVE-2025-14440
JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie
CRITICAL 9.8 2025-12-13
jayarsiech JAY Login & Register
CVE NVD
CVE-2025-14508
MediaCommander – Bring Folders to Media, Posts, and Pages <= 2.3.1 - Missing Authorization to Authenticated (Author+) Media Folder Deletion
MEDIUM 6.5 2025-12-13
yalogica MediaCommander – Bring Folders to Media, Posts, and Pages
CVE NVD
CVE-2025-14539
Shortcode Loader <= 1.0 - Unauthenticated Arbitrary Shortcode Execution via 'code' Parameter
MEDIUM 5.4 2025-12-13
rang501 Shortcode Ajax
CVE NVD
CVE-2025-8617
YITH WooCommerce Quick View <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view Shortcode
MEDIUM 6.4 2025-12-13
yithemes YITH WooCommerce Quick View
CVE NVD
CVE-2025-14367
Easy Theme Options <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Import
MEDIUM 5.3 2025-12-13
corsonr Easy Theme Options
CVE NVD
CVE-2025-7058
Kingcabs <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Parameter
MEDIUM 6.4 2025-12-13
sparklewpthemes Kingcabs
CVE NVD
CVE-2025-12076
Social Media Auto Publish <= 3.6.5 - Reflected Cross-Site Scripting via PostMessage
MEDIUM 6.1 2025-12-13
f1logic Social Media Auto Publish
CVE NVD
CVE-2025-13093
Devs CRM – Manage tasks, attendance and teams all together <= 1.1.8 - Missing Authorization to Unauthenticated Lead Tag Update
MEDIUM 5.3 2025-12-13
ajitdas Devs CRM – Manage tasks, attendance and teams all together
CVE NVD
CVE-2025-13077
افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce <= 1.3.5 - Unauthenticated Time-Based Blind SQL Injection
HIGH 7.5 2025-12-13
payamito افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce
CVE NVD
CVE-2025-14451
Solutions Ad Manager <= 1.0.0 - Unauthenticated Open Redirect via 'sam-redirect-to' Parameter
MEDIUM 4.7 2025-12-13
solutionsbysteve Solutions Ad Manager
CVE NVD
CVE-2025-9218
rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function
LOW 3.7 2025-12-13
rtcamp rtMedia for WordPress, BuddyPress and bbPress
CVE NVD
CVE-2025-14288
Gallery Blocks with Lightbox <= 3.3.0 - Missing Authorization to Authenticated (Contributor+) Plugin Settings Modification
MEDIUM 4.3 2025-12-13
gallerycreator Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery
CVE NVD
CVE-2025-13705
Custom Frames <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Parameter
MEDIUM 6.4 2025-12-13
blakelong Custom Frames
CVE NVD
CVE-2025-14476
Doubly <= 1.0.46 - Authenticated (Subscriber+) PHP Object Injection via ZIP File Import
HIGH 8.8 2025-12-13
unitecms Doubly – Cross Domain Copy Paste for WordPress
CVE NVD
CVE-2025-14475
Extensive VC Addons for WPBakery page builder <= 1.9.1 - Unauthenticated Local File Inclusion via 'shortcode_name' Parameter
HIGH 8.1 2025-12-13
nenad-obradovic Extensive VC Addons for WPBakery page builder
CVE NVD
CVE-2025-14462
Lucky Draw Contests <= 4.2 - Cross-Site Request Forgery to Plugin Settings Update
MEDIUM 4.3 2025-12-13
owais4377 Lucky Draw Contests
CVE NVD
CVE-2025-11376
Colibri Page Builder <= 1.0.335 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-12-13
extendthemes Colibri Page Builder
CVE NVD
CVE-2025-13094
WP3D Model Import Viewer <= 1.0.7 - Authenticated (Contributor+) Arbitrary File Upload
HIGH 8.8 2025-12-13
wp3d WP3D Model Import Viewer
CVE NVD