Recent Advisories

Severity ID Title Vendor Product Date Type
Unknown ADV-3297

CVE-2025-3921 PeproDev Ultimate Profile Solutions 1.9.1 – 7.5.2 – Missing Authorization to Limited Unauthenticated Arbitrary User Meta Update via handel_ajax_req Function

Vulnerability Details Basic Information Title CVE-2025-3921 PeproDev Ultimate Profile Solutions 1.9.1 – 7.5.2 – Missing Authorization t...

N/A N/A NEWS
Unknown ADV-3296

CVE-2025-3852 WPshop 2 – E-Commerce 2.0.0 – 2.6.0 – Authenticated (Subscriber+) Privilege Escalation via Account Takeover

Vulnerability Details Basic Information Title CVE-2025-3852 WPshop 2 – E-Commerce 2.0.0 – 2.6.0 – Authenticated (Subscriber+) Privilege...

N/A N/A NEWS
Unknown ADV-3295

CVE-2025-4335 Woocommerce Multiple Addresses <= 1.0.7.1 - Authenticated (Subscriber+) Privilege Escalation

Vulnerability Details Basic Information Title CVE-2025-4335 Woocommerce Multiple Addresses

N/A N/A NEWS
Unknown ADV-3294

CVE-2025-4055 Multiple Post Type Order <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via mpto Shortcode

Vulnerability Details Basic Information Title CVE-2025-4055 Multiple Post Type Order

N/A N/A NEWS
Unknown ADV-3293

CVE-2025-3860 CarDealerPress <= 6.7.2504.00 - Authenticated (Contributor+) Stored Cross-Site Scripting via saleclass Parameter

Vulnerability Details Basic Information Title CVE-2025-3860 CarDealerPress

N/A N/A NEWS
Unknown ADV-3292

CVE-2025-4220 Xavin’s List Subpages <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Vulnerability Details Basic Information Title CVE-2025-4220 Xavin’s List Subpages

N/A N/A NEWS
Unknown ADV-3291

CVE-2025-4054 Relevanssi <= 4.24.3 - Unauthenticated Stored Cross-Site Scripting via Search Highlights

Vulnerability Details Basic Information Title CVE-2025-4054 Relevanssi

N/A N/A NEWS
Unknown ADV-3290

CVE-2025-3218

Vulnerability Details Basic Information Title CVE-2025-3218 Type cve Published 2025-05-07T02:15:31 Last Seen 2025-05-07T02:23:10 CVSS Score 5.4 (ME...

N/A N/A NEWS
Unknown ADV-3289

Fake SSA Emails Trick Users into Installing ScreenConnect RAT

Security Update News Update Information Title Fake SSA Emails Trick Users into Installing ScreenConnect RAT Update ID HACKREAD:10467E2E6C4A20985A6A...

N/A N/A NEWS
Unknown ADV-3288

CVE-2025-22873

Vulnerability Details Basic Information Title CVE-2025-22873 Type cve Published 2025-05-06T20:33:01 Last Seen 2025-05-06T23:30:19 CVSS Score 0.0 ()...

N/A N/A NEWS