Stay Protected with Vulnerability Alerts

    Updated automatically every hour

    Recent WordPress Vulnerabilities

    Latest WordPress security vulnerabilities affecting plugins, themes, and core.

    MEDIUM (5.2)
    Plugin

    Stored Cross-Site Scripting in Related Posts Lite Plugin

    Published Date: 10/18/2025

    The Related Posts Lite plugin for WordPress contains a vulnerability that allows stored Cross-Site Scripting (XSS) attacks. This vulnerability affects versions up to 1.12 and allows authenticated users with administrator-level permissions to inject malicious scripts via the plugin's admin settings.

    MEDIUM (6.2)
    Plugin

    Sensitive Information Disclosure in PowerBI Embed Reports Plugin for WordPress

    Published Date: 10/18/2025

    The PowerBI Embed Reports plugin for WordPress has a vulnerability that allows unauthorized access to sensitive Azure Active Directory user information. This issue affects all plugin versions up to 1.2.0 and involves the 'testUser' endpoint, which lacks proper capability checks and authentication measures.

    MEDIUM (5.6)
    Plugin

    Unauthorized Data Modification in Kognetiks Chatbot Plugin

    Published Date: 10/18/2025

    The Kognetiks Chatbot plugin for WordPress contains a vulnerability that allows unauthorized modification of data due to absent capability checks. This flaw exists in all versions up to, and including, 2.3.5, enabling unauthenticated users to upload limited safe files and delete conversations.

    MEDIUM (7.0)
    Plugin

    SQL Injection Vulnerability in PPOM WooCommerce Plugin

    Published Date: 10/18/2025

    The PPOM – Product Addons & Custom Fields for WooCommerce plugin is affected by an SQL Injection vulnerability in all versions up to 33.0.15. This vulnerability stems from improper input handling in the `PPOM_Meta::get_fields_by_id()` function, which could allow unauthorized users to perform malicious SQL queries if a specific setting is enabled.

    MEDIUM (5.1)
    Plugin

    Privilege Escalation via Missing Capability Checks in LearnPress Plugin

    Published Date: 10/18/2025

    The LearnPress WordPress LMS Plugin is susceptible to unauthorized data modification due to inadequate capability checks on its admin REST endpoints. This vulnerability permits unauthenticated users to execute harmful database operations, such as dropping indexes and altering site data.

    MEDIUM (6.6)
    Plugin

    Arbitrary File Upload Vulnerability in PPOM – Product Addons & Custom Fields for WooCommerce Plugin

    Published Date: 10/18/2025

    The PPOM - Product Addons & Custom Fields for WooCommerce plugin is vulnerable to arbitrary file uploads due to missing file type validation in its image cropper functionality in versions up to 33.0.15. This flaw allows unauthenticated attackers to potentially upload files that can lead to remote code execution on sites using the paid version of the plugin.

    MEDIUM (6.8)
    Plugin

    Stored Cross-Site Scripting Vulnerability in Gutenberg Essential Blocks Plugin

    Published Date: 10/18/2025

    The Gutenberg Essential Blocks plugin for WordPress has a Stored Cross-Site Scripting (XSS) vulnerability in the 'titleTag' attribute, affecting versions up to 5.7.1. This vulnerability allows authenticated users with Contributor-level permissions to inject malicious scripts.

    MEDIUM (5.2)
    Plugin

    Insecure Direct Object Reference in Optimole Plugin REST API Endpoint

    Published Date: 10/18/2025

    The Optimole WordPress plugin is vulnerable to an Insecure Direct Object Reference (IDOR) issue in its /wp-json/optml/v1/move_image REST API endpoint. This flaw allows authenticated users with at least Author-level permissions to manipulate media they do not own.

    MEDIUM (6.4)
    Plugin

    Unauthorized Data Modification in FileBird Plugin Due to Missing Capability Check

    Published Date: 10/18/2025

    The FileBird WordPress plugin is vulnerable to unauthorized data modification, allowing authenticated users with author-level access and above to reset the plugin's configuration. This issue arises due to a missing capability check on a specific function, affecting all versions up to 6.4.9.

    MEDIUM (5.7)
    Plugin

    WP Go Maps Plugin Vulnerable to Cache Poisoning

    Published Date: 10/18/2025

    The WP Go Maps plugin for WordPress, up to version 9.0.48, is susceptible to a Cache Poisoning vulnerability. This flaw allows unauthenticated users to manipulate the cache for location search results by exploiting how the plugin handles user input.

    MEDIUM (5.8)
    Plugin

    Stored Cross-Site Scripting Vulnerability in WPBakery Page Builder via RevSlider Shortcode

    Published Date: 10/18/2025

    The WPBakery Page Builder plugin up to version 8.6 is vulnerable to Stored Cross-Site Scripting through the 'rev_slider_vc' shortcode when RevSlider is also installed. This vulnerability allows attackers with contributor-level access and above to inject arbitrary scripts into a page, which will execute when the page is viewed.

    MEDIUM (5.3)
    Plugin

    SQL Injection Vulnerability in GSpeech TTS WordPress Plugin

    Published Date: 10/18/2025

    The GSpeech TTS – WordPress Text To Speech Plugin is vulnerable to SQL Injection via the 'field' parameter up to version 3.17.13. This vulnerability allows attackers with Administrator-level access to manipulate SQL queries and potentially extract sensitive information from the database.

    MEDIUM (6.5)
    Plugin

    Information Exposure in WPC Smart Quick View for WooCommerce Plugin

    Published Date: 10/18/2025

    The WPC Smart Quick View for WooCommerce plugin is susceptible to an information exposure vulnerability affecting all versions up to and including 4.2.5. The vulnerability allows unauthorized users to obtain data from password-protected, private, or draft products via the 'woosq_quickview' AJAX endpoint.

    MEDIUM (6.6)
    Plugin

    Payment Bypass Vulnerability in Event Tickets and Registration Plugin

    Published Date: 10/18/2025

    The Event Tickets and Registration plugin for WordPress contains a payment bypass vulnerability in versions up to 5.26.5. This flaw allows unauthenticated users to exploit the endpoint handling free orders, thereby gaining access to paid tickets without payment.

    MEDIUM (6.9)
    Plugin

    Unauthorized Data Access in WPC Smart Wishlist for WooCommerce Plugin

    Published Date: 10/18/2025

    The WPC Smart Wishlist for WooCommerce plugin suffers from unauthorized access vulnerabilities due to a missing capability check on the 'wishlist_quickview' AJAX action. This issue affects versions up to 5.0.4, allowing Subscriber-level users to access other users' wishlist data.

    MEDIUM (5.6)
    Plugin

    Stored Cross-Site Scripting in XX2WP Integration Tools Shortcode

    Published Date: 10/18/2025

    The XX2WP Integration Tools plugin is vulnerable to stored cross-site scripting due to improper sanitization of input in the 'mxp_fb2wp_display_embed' shortcode. This allows users with contributor-level access or above to inject malicious scripts into WordPress pages.

    MEDIUM (5.7)
    Plugin

    Media Library Assistant Plugin File Reading Vulnerability

    Published Date: 10/18/2025

    The Media Library Assistant plugin for WordPress contains a vulnerability that allows unauthenticated users to read the contents of certain files on the server. This issue affects all versions up to and including 3.29, making it possible to access sensitive data stored in ai, eps, pdf, and ps files.

    MEDIUM (5.4)
    Plugin

    Server-Side Request Forgery in Gutenberg Essential Blocks Plugin

    Published Date: 10/18/2025

    The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin is affected by a Server-Side Request Forgery (SSRF) vulnerability up to version 5.7.1. This issue allows authenticated users with at least Author-level privileges to initiate requests to arbitrary locations, potentially leading to unauthorized interactions with internal systems.

    MEDIUM (6.7)
    Plugin

    Unauthorized Data Modification in ShortPixel Image Optimizer Plugin

    Published Date: 10/18/2025

    The ShortPixel Image Optimizer plugin for WordPress, up to version 6.3.4, allows unauthorized modification of data due to a missing capability check on an AJAX action. This vulnerability can be exploited by authenticated users with at least Contributor-level access.

    MEDIUM (6.1)
    Plugin

    Insecure Direct Object Reference in Binary MLM Plan Plugin

    Published Date: 10/17/2025

    The Binary MLM Plan plugin vulnerability arises from an insecure direct object reference, allowing authenticated users with the bmp_user role to access other users' payout details. This flaw is present in versions up to and including 3.0 and involves improper access controls in the payout detail function.

    MEDIUM (6.7)
    Plugin

    Felan Framework Plugin Unauthorized Plugin Activation/Deactivation

    Published Date: 10/16/2025

    The Felan Framework plugin for WordPress up to version 1.1.4 allows unauthorized users to change the state of installed plugins due to missing capability checks in an AJAX action. This could enable unauthenticated users to activate or deactivate plugins, potentially impacting site functionality.

    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2025 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More