漏洞列表 350844
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-14375
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className
MEDIUM 6.1 2026-01-16
rebelcode RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
CVE NVD
CVE-2026-1003
GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools <= 4.3.0 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion
MEDIUM 4.3 2026-01-16
roxnor GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools
CVE NVD
CVE-2025-14793
DK PDF – WordPress PDF Generator <= 2.3.0 - Authenticated (Author+) Server-Side Request Forgery
MEDIUM 5.0 2026-01-16
torstenbulk DK PDF – WordPress PDF Generator
CVE NVD
CVE-2025-14853
LEAV Last Email Address Validator <= 1.7.1 - Cross-Site Request Forgery to Plugin Settings Update
MEDIUM 4.3 2026-01-16
smings LEAV Last Email Address Validator
CVE NVD
CVE-2026-0939
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.2 - Unauthenticated Order Status Manipulation
MEDIUM 5.3 2026-01-16
linknacional Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit
CVE NVD
CVE-2026-0942
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.2 - Missing Authorization to Unauthenticated Rede Order Logs Deletion
MEDIUM 5.3 2026-01-16
linknacional Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit
CVE NVD
CVE-2026-0916
Related Posts by Taxonomy <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'related_posts_by_tax' Shortcode
MEDIUM 6.4 2026-01-16
keesiemeijer Related Posts by Taxonomy
CVE NVD
CVE-2026-0975
DIAView - Command Injection Vulnerability
HIGH 7.8 2026-01-16
Delta Electronics DIAView
CVE NVD
CVE-2026-23769
lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to impr...
MEDIUM 6.5 2026-01-16
NAVER lucy-xss-filter
CVE NVD
CVE-2026-23768
lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbi...
MEDIUM 6.1 2026-01-16
NAVER lucy-xss-filter
CVE NVD
CVE-2026-0858
Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored X...
MEDIUM 5.1 2026-01-16
未知
CVE NVD
CVE-2025-14384
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure
MEDIUM 4.3 2026-01-16
smub All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
CVE NVD
CVE-2026-1000
MailerLite - WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion
MEDIUM 6.5 2026-01-16
mailerlite MailerLite – WooCommerce integration
CVE NVD
CVE-2025-15370
Shield Security <= 21.0.9 - Authenticated (Subscriber+) Insecure Direct Object Reference to Disable Google Authenticator
MEDIUM 4.3 2026-01-16
paultgoodchild Shield: Blocks Bots, Protects Users, and Prevents Security Breaches
CVE NVD
CVE-2025-12957
All-in-One Video Gallery <= 4.5.7 - Authenticated (Author+) Arbitrary File Upload via VTT Upload Bypass
HIGH 8.8 2026-01-16
plugins360 All-in-One Video Gallery
CVE NVD
CVE-2025-12641
Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion
MEDIUM 6.5 2026-01-16
awesomesupport Awesome Support – WordPress HelpDesk & Support Plugin
CVE NVD
CVE-2025-15526
Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Full Path Disclosure via 'pdf' Parameter
MEDIUM 5.3 2026-01-16
radykal Fancy Product Designer
CVE NVD
CVE-2025-15527
WP Recipe Maker <= 10.2.2 - Insecure Direct Object Reference to Sensitive Information Exposure
MEDIUM 4.3 2026-01-16
brechtvds WP Recipe Maker
CVE NVD
CVE-2025-14982
Booking Calendar <= 10.14.11 - Missing Authorization to Sensitive Information Exposure
MEDIUM 4.3 2026-01-16
wpdevelop Booking Calendar
CVE NVD
CVE-2026-1023
Gotac|Statistics Database System - Missing Authentication
HIGH 8.7 2026-01-16
Gotac Statistics Database System
CVE NVD