Recent Advisories

Severity ID Title Vendor Product Date Type
Unknown ADV-3303

CVE-2025-3766 Login Lockdown & Protection <= 2.11 - Missing Authorization to Authenticated (Subscriber+) Arbitrary IP Whitelisting

Vulnerability Details Basic Information Title CVE-2025-3766 Login Lockdown & Protection

N/A N/A NEWS
Unknown ADV-3302

CVE-2025-2821 Search Exclude <= 2.4.9 - Missing Authorization to Unauthenticated Plugin Settings Modification

Vulnerability Details Basic Information Title CVE-2025-2821 Search Exclude

N/A N/A NEWS
Unknown ADV-3301

CVE-2025-3853 WPshop 2 – E-Commerce 2.0.0 – 2.6.0 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Key Generation

Vulnerability Details Basic Information Title CVE-2025-3853 WPshop 2 – E-Commerce 2.0.0 – 2.6.0 – Insecure Direct Object Reference to A...

N/A N/A NEWS
Unknown ADV-3300

CVE-2025-3924 PeproDev Ultimate Profile Solutions 1.9.1 – 7.5.2 – Missing Authorization to Unauthenticated Email Enumeration

Vulnerability Details Basic Information Title CVE-2025-3924 PeproDev Ultimate Profile Solutions 1.9.1 – 7.5.2 – Missing Authorization t...

N/A N/A NEWS
Unknown ADV-3299

CVE-2025-3851 Download Manager and Payment Form WordPress Plugin – WP SmartPay 1.1.0 – 2.7.13 – Authenticated (Subscriber+) Information Exposure

Vulnerability Details Basic Information Title CVE-2025-3851 Download Manager and Payment Form WordPress Plugin – WP SmartPay 1.1.0 – 2.7.13 &...

N/A N/A NEWS
Unknown ADV-3298

CVE-2025-3844 PeproDev Ultimate Profile Solutions 1.9.1 – 7.5.2 – Authentication Bypass to Account Takeover

Vulnerability Details Basic Information Title CVE-2025-3844 PeproDev Ultimate Profile Solutions 1.9.1 – 7.5.2 – Authentication Bypass t...

N/A N/A NEWS
Unknown ADV-3297

CVE-2025-3921 PeproDev Ultimate Profile Solutions 1.9.1 – 7.5.2 – Missing Authorization to Limited Unauthenticated Arbitrary User Meta Update via handel_ajax_req Function

Vulnerability Details Basic Information Title CVE-2025-3921 PeproDev Ultimate Profile Solutions 1.9.1 – 7.5.2 – Missing Authorization t...

N/A N/A NEWS
Unknown ADV-3296

CVE-2025-3852 WPshop 2 – E-Commerce 2.0.0 – 2.6.0 – Authenticated (Subscriber+) Privilege Escalation via Account Takeover

Vulnerability Details Basic Information Title CVE-2025-3852 WPshop 2 – E-Commerce 2.0.0 – 2.6.0 – Authenticated (Subscriber+) Privilege...

N/A N/A NEWS
Unknown ADV-3295

CVE-2025-4335 Woocommerce Multiple Addresses <= 1.0.7.1 - Authenticated (Subscriber+) Privilege Escalation

Vulnerability Details Basic Information Title CVE-2025-4335 Woocommerce Multiple Addresses

N/A N/A NEWS
Unknown ADV-3294

CVE-2025-4055 Multiple Post Type Order <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via mpto Shortcode

Vulnerability Details Basic Information Title CVE-2025-4055 Multiple Post Type Order

N/A N/A NEWS