{"id":1409,"date":"2025-04-24T09:32:47","date_gmt":"2025-04-24T09:32:47","guid":{"rendered":"http:\/\/localhost\/?p=1409"},"modified":"2025-04-24T09:32:47","modified_gmt":"2025-04-24T09:32:47","slug":"wordfence-intelligence-weekly-wordpress-vulnerability-report-april-14-2025-to-april-20-2025","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=1409","title":{"rendered":"Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025)"},"content":{"rendered":"<div class=\"vulnerability-details\">\n<h2>Vulnerability Details<\/h2>\n<div class=\"info-section\">\n<h3>Basic Information<\/h3>\n<table class=\"info-table\">\n<tr>\n<th>Title<\/th>\n<td>Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025)<\/td>\n<\/tr>\n<tr>\n<th>Type<\/th>\n<td>wordfence<\/td>\n<\/tr>\n<tr>\n<th>Published<\/th>\n<td>2025-04-24T13:46:39<\/td>\n<\/tr>\n<tr>\n<th>Last Seen<\/th>\n<td>2025-04-24T13:53:27<\/td>\n<\/tr>\n<tr>\n<th>CVSS Score<\/th>\n<td style=\"color: #cc0000; font-weight: bold;\">10.0 (CRITICAL)<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"cvss-section\">\n<h3>CVSS v3 Details<\/h3>\n<table class=\"cvss-table\">\n<tr>\n<th>Attack Vector<\/th>\n<td>NETWORK<\/td>\n<\/tr>\n<tr>\n<th>Attack Complexity<\/th>\n<td>LOW<\/td>\n<\/tr>\n<tr>\n<th>Privileges Required<\/th>\n<td>NONE<\/td>\n<\/tr>\n<tr>\n<th>User Interaction<\/th>\n<td>NONE<\/td>\n<\/tr>\n<tr>\n<th>Scope<\/th>\n<td>CHANGED<\/td>\n<\/tr>\n<tr>\n<th>Confidentiality Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<tr>\n<th>Integrity Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<tr>\n<th>Availability Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"cve-section\">\n<h3>CVE Information<\/h3>\n<table class=\"cve-table\">\n<tr>\n<th>CVE IDs<\/th>\n<td>CVE-2024-13452, CVE-2024-13650, CVE-2025-1093, CVE-2025-1457, CVE-2025-2010, CVE-2025-2083, CVE-2025-2111, CVE-2025-2225, CVE-2025-22774, CVE-2025-2314, CVE-2025-23958, CVE-2025-2613, CVE-2025-26730, CVE-2025-26735, CVE-2025-26872, CVE-2025-26889, CVE-2025-26892, CVE-2025-26942, CVE-2025-26944, CVE-2025-26953, CVE-2025-26954, CVE-2025-26958, CVE-2025-26968, CVE-2025-26992, CVE-2025-26996, CVE-2025-27008, CVE-2025-27009, CVE-2025-27010, CVE-2025-3056, CVE-2025-3077, CVE-2025-30960, CVE-2025-3103, CVE-2025-3104, CVE-2025-3106, CVE-2025-3247, CVE-2025-32486, CVE-2025-32507, CVE-2025-32508, CVE-2025-32513, CVE-2025-32527, CVE-2025-32540, CVE-2025-32545, CVE-2025-32546, CVE-2025-32561, CVE-2025-32571, CVE-2025-32572, CVE-2025-32573, CVE-2025-32583, CVE-2025-32592, CVE-2025-32596, CVE-2025-32602, CVE-2025-32605, CVE-2025-32608, CVE-2025-32609, CVE-2025-32622, CVE-2025-32626, CVE-2025-32634, CVE-2025-32635, CVE-2025-32636, CVE-2025-32637, CVE-2025-32638, CVE-2025-32647, CVE-2025-32648, CVE-2025-32657, CVE-2025-32658, CVE-2025-32660, CVE-2025-32662, CVE-2025-32665, CVE-2025-32666, CVE-2025-32682, CVE-2025-32686, CVE-2025-32688, CVE-2025-3275, CVE-2025-3278, CVE-2025-3284, CVE-2025-32923, CVE-2025-32929, CVE-2025-3294, CVE-2025-3295, CVE-2025-3404, CVE-2025-3453, CVE-2025-3470, CVE-2025-3479, CVE-2025-3487, CVE-2025-3520, CVE-2025-3598, CVE-2025-3615, CVE-2025-3661, CVE-2025-3809, CVE-2025-39351, CVE-2025-39353, CVE-2025-39381, CVE-2025-39385, CVE-2025-39388, CVE-2025-39390, CVE-2025-39392, CVE-2025-39394, CVE-2025-39395, CVE-2025-39396, CVE-2025-39401, CVE-2025-39402, CVE-2025-39403, CVE-2025-39404, CVE-2025-39405, CVE-2025-39406, CVE-2025-39407, CVE-2025-39408, CVE-2025-39409, CVE-2025-39410, CVE-2025-39411, CVE-2025-39412, CVE-2025-39413, CVE-2025-39414, CVE-2025-39415, CVE-2025-39416, CVE-2025-39418, CVE-2025-39419, CVE-2025-39420, CVE-2025-39421, CVE-2025-39422, CVE-2025-39423, CVE-2025-39424, CVE-2025-39425, CVE-2025-39426, CVE-2025-39427, CVE-2025-39428, CVE-2025-39429, CVE-2025-39430, CVE-2025-39431, CVE-2025-39432, CVE-2025-39433, CVE-2025-39434, CVE-2025-39435, CVE-2025-39436, CVE-2025-39437, CVE-2025-39438, CVE-2025-39439, CVE-2025-39440, CVE-2025-39441, CVE-2025-39442, CVE-2025-39443, CVE-2025-39444, CVE-2025-39445, CVE-2025-39446, CVE-2025-39447, CVE-2025-39448, CVE-2025-39449, CVE-2025-39450, CVE-2025-39451, CVE-2025-39452, CVE-2025-39453, CVE-2025-39454, CVE-2025-39455, CVE-2025-39456, CVE-2025-39457, CVE-2025-39458, CVE-2025-39459, CVE-2025-39460, CVE-2025-39461, CVE-2025-39462, CVE-2025-39463, CVE-2025-39464, CVE-2025-39465, CVE-2025-39466, CVE-2025-39467, CVE-2025-39468, CVE-2025-39469, CVE-2025-39470, CVE-2025-39471, CVE-2025-39472, CVE-2025-39512, CVE-2025-39513, CVE-2025-39514, CVE-2025-39515, CVE-2025-39516, CVE-2025-39517, CVE-2025-39518, CVE-2025-39519, CVE-2025-39520, CVE-2025-39521, CVE-2025-39522, CVE-2025-39523, CVE-2025-39524, CVE-2025-39525, CVE-2025-39526, CVE-2025-39527, CVE-2025-39528, CVE-2025-39529, CVE-2025-39530, CVE-2025-39533, CVE-2025-39535, CVE-2025-39538, CVE-2025-39540, CVE-2025-39541, CVE-2025-39542, CVE-2025-39543, CVE-2025-39544, CVE-2025-39545, CVE-2025-39546, CVE-2025-39547, CVE-2025-39548, CVE-2025-39549, CVE-2025-39550, CVE-2025-39551, CVE-2025-39553, CVE-2025-39554, CVE-2025-39555, CVE-2025-39556, CVE-2025-39557, CVE-2025-39558, CVE-2025-39559, CVE-2025-39560, CVE-2025-39562, CVE-2025-39563, CVE-2025-39564, CVE-2025-39565, CVE-2025-39566, CVE-2025-39567, CVE-2025-39568, CVE-2025-39569, CVE-2025-39570, CVE-2025-39571, CVE-2025-39572, CVE-2025-39573, CVE-2025-39574, CVE-2025-39575, CVE-2025-39576, CVE-2025-39577, CVE-2025-39578, CVE-2025-39579, CVE-2025-39580, CVE-2025-39581, CVE-2025-39582, CVE-2025-39583, CVE-2025-39584, CVE-2025-39585, CVE-2025-39586, CVE-2025-39587, CVE-2025-39588, CVE-2025-39589, CVE-2025-39590, CVE-2025-39592, CVE-2025-39593, CVE-2025-39594, CVE-2025-39595, CVE-2025-39596, CVE-2025-39597, CVE-2025-39598, CVE-2025-39599, CVE-2025-39600, CVE-2025-39601<\/td>\n<\/tr>\n<tr>\n<th>CWE<\/th>\n<td><\/td>\n<\/tr>\n<tr>\n<th>Bulletin Family<\/th>\n<td>info<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"description-section\">\n<h3>Description<\/h3>\n<div class=\"description-content\">\n            * * *<\/p>\n<p>_![\ud83d\udce2](https:\/\/s.w.org\/images\/core\/emoji\/15.0.3\/72&#215;72\/1f4e2.png)**In case you missed it, Wordfence just published itsannual WordPress security report for 2024. Read it now to learn more about the evolving risk landscape of WordPress so you can keep your sites protected in 2025 and beyond. **_<\/p>\n<p>* * *<\/p>\n<p>Last week, there were 252 vulnerabilities disclosed in 215 WordPress Plugins and 15 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 56 Vulnerability Researchers that contributed to WordPress Security last week. **Review those vulnerabilities in this report now to ensure your site is not affected.**<\/p>\n<p>Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data**to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies.** That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.<\/p>\n<p>Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our **database of over 25,000 vulnerabilities** and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, **all for free**.<\/p>\n<p>_Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published._<\/p>\n<p>* * *<\/p>\n<p>### New Firewall Rules Deployed Last Week<\/p>\n<p>The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.<\/p>\n<p>The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:<\/p>\n<p>  * WAF-RULE-821 &#8211; Data redacted while we work with the vendor on a patch.<\/p>\n<p>Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.<\/p>\n<p>* * *<\/p>\n<p>### Total Unpatched &#038; Patched Vulnerabilities Last Week<\/p>\n<p>Patch Status | Number of Vulnerabilities<br \/>\n&#8212;|&#8212;<br \/>\nPatched | 137<br \/>\nUnpatched | 115  <\/p>\n<p>* * *<\/p>\n<p>### Total Vulnerabilities by CVSS Severity Last Week<\/p>\n<p>Severity Rating | Number of Vulnerabilities<br \/>\n&#8212;|&#8212;<br \/>\nLow Severity | 1<br \/>\nMedium Severity | 179<br \/>\nHigh Severity | 42<br \/>\nCritical Severity | 30  <\/p>\n<p>* * *<\/p>\n<p>### Total Vulnerabilities by CWE Type Last Week<\/p>\n<p>Vulnerability Type by CWE | Number of Vulnerabilities<br \/>\n&#8212;|&#8212;<br \/>\nImproper Neutralization of Input During Web Page Generation (&#8216;Cross-site Scripting&#8217;) | 79<br \/>\nCross-Site Request Forgery (CSRF) | 44<br \/>\nMissing Authorization | 35<br \/>\nImproper Control of Filename for Include\/Require Statement in PHP Program (&#8216;PHP Remote File Inclusion&#8217;) | 21<br \/>\nImproper Neutralization of Special Elements used in an SQL Command (&#8216;SQL Injection&#8217;) | 17<br \/>\nDeserialization of Untrusted Data | 12<br \/>\nUnrestricted Upload of File with Dangerous Type | 10<br \/>\nExposure of Sensitive Information to an Unauthorized Actor | 8<br \/>\nImproper Limitation of a Pathname to a Restricted Directory (&#8216;Path Traversal&#8217;) | 6<br \/>\nImproper Privilege Management | 6<br \/>\nImproper Control of Generation of Code (&#8216;Code Injection&#8217;) | 4<br \/>\nURL Redirection to Untrusted Site (&#8216;Open Redirect&#8217;) | 4<br \/>\nAuthorization Bypass Through User-Controlled Key | 2<br \/>\nImproper Validation of Integrity Check Value | 2<br \/>\nExternal Control of File Name or Path | 1<br \/>\nIncorrect Authorization | 1  <\/p>\n<p>* * *<\/p>\n<p>### Researchers That Contributed to WordPress Security Last Week<\/p>\n<p>Researcher Name | Number of Vulnerabilities<br \/>\n&#8212;|&#8212;<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g) johska | 22<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g) stealthcopter | 18<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g) muhammad yudha | 17<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g) Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc) | 17<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g) Nguyen Xuan Chien | 14<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) LVT-tholv2k | 13<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) Bonds | 13<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g) 0xd4rk5id3 | 11<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) astra.r3verii | 9<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&#038;d=mp&#038;r=g) Nabil Irawan | 8<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/385d41daf781fbf4dbac2a1ff894d7fc.jpg?s=32&#038;d=mp&#038;r=g) Le Ngoc Anh | 8<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) Ananda Dhakal | 7<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/01dce303f1fab51371215f21992679d9.jpg?s=32&#038;d=mp&#038;r=g) theviper17y | 6<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&#038;d=mp&#038;r=g) Jo\u00e3o Pedro Soares de Alc\u00e2ntara | 6<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/b5bd58d8a8029c69877dc8a75d7889fd.jpg?s=32&#038;d=mp&#038;r=g) K\u00e9vin Mosbahi (Mika) | 6<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/f1b68a12f61846b7fbcd7f1338106a1f.jpg?s=32&#038;d=mp&#038;r=g) Dimas Maulana | 5<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/258c774aecd81b7d1fa67abf3b576b33.jpg?s=32&#038;d=mp&#038;r=g) Peter Thaleikis | 5<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/11dfabc58a06f06c9123a7e17a41cecb.jpg?s=32&#038;d=mp&#038;r=g) Aiden (Th\u00e1i An) | 5<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/e4a8b174c9f284d94094cf7722e1ec31.jpg?s=32&#038;d=mp&#038;r=g) Asaf Mozes | 4<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) Phan Trong Quan | 4<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/ef74f4dbe7907a62f177592f647c1afa.jpg?s=32&#038;d=mp&#038;r=g) Webbernaut | 4<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/54d48d97cbd2b84eb914943109eb7d14.jpg?s=32&#038;d=mp&#038;r=g) Nguy\u1ec5n Trung Ki\u00ean | 4<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/4c2bd6964b38518385c4e8d1791fd762.jpg?s=32&#038;d=mp&#038;r=g) zaim | 3<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/c36a7211a54c34d3d52be3b1bd8d253e.jpg?s=32&#038;d=mp&#038;r=g) lucky_buddy | 3<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) Skalucy | 3<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/c070414ac7706c1f7345b025f413df56.jpg?s=32&#038;d=mp&#038;r=g) Brian Sans-Souci (liardom) | 2<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/5a1c57ff7dc66a0d8702f856ceb355fd.jpg?s=32&#038;d=mp&#038;r=g) the sneaky squirrel | 2<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/c14731a0f8a0d24cbda30f561fc03441.jpg?s=32&#038;d=mp&#038;r=g) SOPROBRO | 2<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/14c9ac0f163cbf6d8b0f77fce5836577.jpg?s=32&#038;d=mp&#038;r=g) wesley (wcraft) | 2<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/37cc74b0e1957fee81825154abeae540.jpg?s=32&#038;d=mp&#038;r=g) nquangit | 2<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/7b8cd550e860295a0dcf86632e3c79be.jpg?s=32&#038;d=mp&#038;r=g) Phat RiO &#8211; BlueRock | 2<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/dfc42784669accf02da36cb658a6a355.jpg?s=32&#038;d=mp&#038;r=g) ch4r0n | 2<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) chuck | 2<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/9d46e040922297c1834a9af4e8278abe.jpg?s=32&#038;d=mp&#038;r=g) khanhhnahk1 | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/0c476cecff9cf0286378f2943694146f.jpg?s=32&#038;d=mp&#038;r=g) Foxyyy | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/4f335379e6c22b34c96df34218ac155f.jpg?s=32&#038;d=mp&#038;r=g) broccoli | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/a964068aac6d7229783a0ea643877251.jpg?s=32&#038;d=mp&#038;r=g) zer0gh0st | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) Doan Dinh Van | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/d30e6a858b269fc0c2ddccf3c3327313.jpg?s=32&#038;d=mp&#038;r=g) haidv35 | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) Deltree | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) Tran Nguyen Bao Khanh | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/80711f5dab8609bebef4ab99b37e869a.jpg?s=32&#038;d=mp&#038;r=g) Carlos Ferreira | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/faefcd06abcb00b4db5324b629c6424e.jpg?s=32&#038;d=mp&#038;r=g) Muhamad Visat | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/2b99835f57008d2a5ee94f41555327d4.jpg?s=32&#038;d=mp&#038;r=g) Alyudin Nafiie | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/697aca1b58dce62b53c47e23b571f54c.jpg?s=32&#038;d=mp&#038;r=g) ayato | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) Pham Van Phuoc | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) domiee13 | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/b20f9553188fa04cbd937e5df1e718af.jpg?s=32&#038;d=mp&#038;r=g) Tim Coen | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) Abdi Pranata | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) tahu.datar | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/1c6327bca62253f0bec06a3d18c37f2a.jpg?s=32&#038;d=mp&#038;r=g) Yassine Neggaoui (Y45NG) | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) Affan Ali | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/7d4a68019ac73014fd7a41bf4de262d6.jpg?s=32&#038;d=mp&#038;r=g) Arshid KV | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/4c8e47602daa5f66a49fdf2c7555c730.jpg?s=32&#038;d=mp&#038;r=g) siavashvafshar | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g) Rafie Muhammad | 1<br \/>\n![](https:\/\/www.gravatar.com\/avatar\/eb428a7b41bcec038cb1bd520e1bc384.jpg?s=32&#038;d=mp&#038;r=g) Prissy | 1  <\/p>\n<p>_Are you a security researcher who would like to be featured in our weekly vulnerability report?_ You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.<\/p>\n<p>* * *<\/p>\n<p>### WordPress Plugins with Reported Vulnerabilities Last Week<\/p>\n<p>Software Name | Software Slug<br \/>\n&#8212;|&#8212;<br \/>\nActiveDEMAND |  activedemand<br \/>\nAdd to Header |  add-to-header<br \/>\nAdministrator Z |  administrator-z<br \/>\nAdminQuickbar |  adminquickbar<br \/>\nAdvanced Dynamic Pricing for WooCommerce |  advanced-dynamic-pricing-for-woocommerce<br \/>\nAI Text to Speech \u2013 TTS Plugin For WordPress |  ai-text-to-speech<br \/>\nAll push notification for WP |  all-push-notification<br \/>\nAmazon Showcase WordPress Plugin |  amazon-showcase-wordpress-widget<br \/>\nAnalyticsWP |  analyticswp<br \/>\nAnthologize |  anthologize<br \/>\nArigato Autoresponder and Newsletter |  bft-autoresponder<br \/>\nAsgaros Forum |  asgaros-forum<br \/>\nAttendance Manager |  attendance-manager<br \/>\nAuthor WIP Progress Bar |  author-work-in-progress-bar<br \/>\nAvatar |  avatar<br \/>\nBarcode Generator for WooCommerce \u2013 Show barcodes on products, orders, invoices and other pages |  embedding-barcodes-into-product-pages-and-orders<br \/>\nBasic Interactive World Map |  basic-interactive-world-map<br \/>\nbbPress2 shortcode whitelist |  bbpress2-shortcode-whitelist<br \/>\nBERTHA AI. Your AI co-pilot for WordPress and Chrome |  bertha-ai-free<br \/>\nBknewsticker |  bknewsticker<br \/>\nBMA Lite \u2013 Appointment Booking and Scheduling Plugin |  bma-lite-appointment-booking-and-scheduling<br \/>\nBooking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment |  booking-and-rental-manager-for-woocommerce<br \/>\nBooster Plus for WooCommerce |  booster-plus-for-woocommerce<br \/>\nBring Fraktguiden for WooCommerce |  bring-fraktguiden-for-woocommerce<br \/>\nBroken Links Remover |  broken-links-remover<br \/>\nBruteGuard \u2013 Brute Force Login Protection |  bruteguard<br \/>\nBulk Page Stub Creator |  bulk-page-stub-creator<br \/>\nBulk Term Editor |  bulk-term-editor<br \/>\nCheckout Files Upload for WooCommerce |  checkout-files-upload-woocommerce<br \/>\nCheckout for PayPal |  checkout-for-paypal<br \/>\nChurch Admin |  church-admin<br \/>\nCLEVER &#8211; HTML5 Radio Player With History &#8211; Shoutcast and Icecast &#8211; Elementor Widget Addon |  elementor_widget_clever_radio_player<br \/>\nCloak Front End Email |  cloak-front-end-email<br \/>\nConditional Payments for WooCommerce |  conditional-payments-for-woocommerce<br \/>\nConditional Shipping for WooCommerce |  conditional-shipping-for-woocommerce<br \/>\nContact Form 7 |  contact-form-7<br \/>\nContact Form by Supsystic |  contact-form-by-supsystic<br \/>\nContact Form vCard Generator |  contact-form-vcard-generator<br \/>\nContact Form, Drag and Drop Form Builder Plugin \u2013 Live Forms |  liveforms<br \/>\nCost Calculator Builder |  cost-calculator-builder<br \/>\nCoupon Affiliates \u2013 Affiliate Plugin for WooCommerce |  woo-coupon-usage<br \/>\nCourse Booking System |  course-booking-system<br \/>\nCRM Perks \u2013 WordPress HelpDesk Integration \u2013 Zendesk, Freshdesk, HelpScout |  support-x<br \/>\nCRUDLab Scroll to Top |  crudlab-scroll-to-top<br \/>\nCustom CSS, JS &#038; PHP |  custom-css<br \/>\nDashboard Notepads |  dashboard-notepads<br \/>\nDashi |  dashi<br \/>\nDebug Log Manager |  debug-log-manager<br \/>\nDirectory Listings WordPress plugin \u2013 uListing |  ulisting<br \/>\nDocket Cache \u2013 Object Cache Accelerator |  docket-cache<br \/>\nDownload Manager |  download-manager<br \/>\nDynamic Post |  dynamic-post<br \/>\nEditor Wysiwyg Background Color |  editor-wysiwyg-background-color<br \/>\nElement Pack Addons for Elementor \u2013 Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder |  bdthemes-element-pack-lite<br \/>\nElementsReady Addons for Elementor |  element-ready-lite<br \/>\nEssential Addons for Elementor \u2013 Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits &#038; WooCommerce Builders |  essential-addons-for-elementor-lite<br \/>\nEvent Espresso \u2013 Custom Email Template Shortcode |  email-shortcode<br \/>\nEvent Manager, Events Calendar, Tickets, Registrations \u2013 Eventin |  wp-event-solution<br \/>\nEver Accounting \u2013 WordPress Accounting and Invoice Plugin |  wp-ever-accounting<br \/>\nFast eBay Listings |  fast-ebay-listings<br \/>\nFeedify \u2013 Web Push Notifications |  push-notification-by-feedify<br \/>\nFluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, &#038; Conversational Form Builder |  fluentform<br \/>\nFluentBoards \u2013 Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration |  fluent-boards<br \/>\nFluentCommunity \u2013 Ultra-Fast High-Performance Social Network, Community, LMS &#038; Online Courses Plugin |  fluent-community<br \/>\nForminator Forms \u2013 Contact Form, Payment Form &#038; Custom Form Builder |  forminator<br \/>\nFS Poster &#8211; WordPress Social media Auto Poster &#038; Scheduler [Facebook, Instagram, Twitter, Pinterest] |  fs-poster<br \/>\nGoodBarber |  goodbarber<br \/>\nGravity Forms CSS Themes with Fontawesome and Placeholders |  gravity-forms-css-themes-with-fontawesome-and-placeholder-support<br \/>\nHelpGent \u2013 The Ultimate Form Builder &#038; TypeForm Alternative on WordPress | Craft Conversational Multi Step Form with Video, Voice, Screen Recording, &#038; Text Messaging |  helpgent<br \/>\nHive Support | AI-Powered Help Desk, Live Chat &#038; AI Chat Bot Plugin for WordPress |  hive-support<br \/>\nhockeydata LOS |  hockeydata-los<br \/>\nHostel |  hostel<br \/>\nHotel Booking |  nd-booking<br \/>\nHTML5 Audio Player- Best WordPress Audio Player Plugin |  html5-audio-player<br \/>\nI Draw |  idraw<br \/>\nillow \u2013 Cookies Consent |  lgpd-compliant-cookie-banner<br \/>\nInsert Headers And Footers |  wp-headers-and-footers<br \/>\nIntegration for WooCommerce and QuickBooks |  wp-woocommerce-quickbooks<br \/>\nIP2Location Variables |  ip2location-variables<br \/>\nJetBlocks for Elementor |  jet-blocks<br \/>\nJetBlog for Elementor |  jet-blog<br \/>\nJetElements |  jet-elements<br \/>\nJetMenu for Elementor |  jet-menu<br \/>\nJetPopup |  jet-popup<br \/>\nJetReviews for Elementor |  jet-reviews<br \/>\nJetTabs for Elementor |  jet-tabs<br \/>\nJetTricks for Elementor |  jet-tricks<br \/>\nJetWooBuilder for Elementor |  jet-woo-builder<br \/>\nJobWP \u2013 Job Board, Job Listing, Career Page and Recruitment Plugin |  jobwp<br \/>\nJS Job Manager |  js-jobs<br \/>\nKadence WooCommerce Email Designer |  kadence-woocommerce-email-designer<br \/>\nKata Plus \u2013 Addons for Elementor \u2013 Widgets, Extensions and Templates |  kata-plus<br \/>\nKiotViet Sync |  kiotvietsync<br \/>\nLA-Studio Element Kit for Elementor |  lastudio-element-kit<br \/>\nLanding Page Cat \u2013 Coming Soon Page, Maintenance Page &#038; Squeeze Pages |  landing-page-cat<br \/>\nListdom \u2013 Business Directory and Classified Ads Listings WordPress Plugin |  listdom<br \/>\nLocal Magic |  local-magic<br \/>\nLogin Manager \u2013 Design Login Page, View Login Activity, Limit Login Attempts |  customized-login<br \/>\nLogo Carousel Gutenberg Block |  awesome-logo-carousel-block<br \/>\nLogo Carousel Slider |  logo-carousel-slider<br \/>\nMacro Calculator with Admin Email Optin &#038; Data |  macro-admin-email-data-optin-calculator<br \/>\nMapSVG \u2013 Vector maps, Image maps, Google Maps |  mapsvg-lite-interactive-vector-maps<br \/>\nMaster Slider \u2013 Responsive Touch Slider |  master-slider<br \/>\nMaterial Dashboard |  material-dashboard<br \/>\nMediavine Control Panel |  mediavine-control-panel<br \/>\nMelaPress Login Security |  melapress-login-security<br \/>\nMemberpress |  memberpress<br \/>\nMembership For WooCommerce |  membership-for-woocommerce<br \/>\nmLanguage |  mlanguage<br \/>\nmodal-survey |  modal-survey<br \/>\nMost And Least Read Posts Widget |  most-and-least-read-posts-widget<br \/>\nMovylo Marketing Automation |  movylo-widget<br \/>\nMy auctions allegro |  my-auctions-allegro-free-edition<br \/>\nMy Marginalia |  my-marginalia<br \/>\nName Directory |  name-directory<br \/>\nOffice Locator |  office-locator<br \/>\nOTP-less one tap Sign in |  otpless<br \/>\nPassword Protected \u2013 Password Protect your WordPress Site, Pages, &#038; WooCommerce Products \u2013 Restrict Content, Protect WooCommerce Category and more |  password-protected<br \/>\nPayment Form for PayPal Pro |  payment-form-for-paypal-pro<br \/>\nPDF 2 Post |  pdf2post<br \/>\nPiotnet Addons For Elementor |  piotnet-addons-for-elementor<br \/>\nProfileGrid \u2013 User Profiles, Groups and Communities |  profilegrid-user-profiles-groups-and-communities<br \/>\nProjectopia \u2013 WordPress Project Management |  projectopia-core<br \/>\nProperty Hive |  propertyhive<br \/>\nQuentn WP |  quentn-wp<br \/>\nQuestion Answer |  question-answer<br \/>\nRating by BestWebSoft |  rating-bws<br \/>\nReal Estate Manager \u2013 Property Listing and Agent Management |  real-estate-manager<br \/>\nRescue Shortcodes |  rescue-shortcodes<br \/>\nResponsive Addons for Elementor \u2013 Free Elementor Addons Plugin and Elementor Templates |  responsive-addons-for-elementor<br \/>\nResponsive Blocks \u2013 WordPress Gutenberg Blocks |  responsive-block-editor-addons<br \/>\nReview Wave \u2013 Google Places Reviews |  review-wave-google-places-reviews<br \/>\nRevision Diet |  revision-diet<br \/>\nRight Click Disable OR Ban |  right-click-disable-or-ban<br \/>\nRoyal Elementor Addons and Templates |  royal-elementor-addons<br \/>\nRSS Manager |  rss-manager<br \/>\nRun Contests, Raffles, and Giveaways with ContestsWP |  contest-code-checker<br \/>\nSB Chart block |  sb-chart-block<br \/>\nScriptless Social Sharing |  scriptless-social-sharing<br \/>\nSell access, Automate, and add Engaging Exclusive Discord Access: Introducing the MemberPress Discord Addon \u2014 Elevate Your Community! |  expresstechsoftwares-memberpress-discord-add-on<br \/>\nShopApper: Mobile App for WooCommerce |  mobile-app-for-woocommerce<br \/>\nSign-up Sheets |  sign-up-sheets<br \/>\nSimple Maps |  interactive-maps<br \/>\nSimple Sitemap \u2013 Create a Responsive HTML Sitemap |  simple-sitemap<br \/>\nSite Search 360 |  site-search-360<br \/>\nSmart Agreements |  smart-agreements<br \/>\nSocial Media Links |  social-media-links<br \/>\nSocial Sharing Plugin \u2013 Sassy Social Share |  sassy-social-share<br \/>\nspam-stopper |  spam-stopper<br \/>\nStarfish Review Generation &#038; Marketing for WordPress |  starfish-reviews<br \/>\nStoreContrl Woocommerce |  storecontrl-wp-connection<br \/>\nStyle Manager \u2013 Auto-magical system to style your entire WordPress site |  style-manager<br \/>\nSubscribe to Unlock Lite \u2013 Opt In Content Locker Plugin for WordPress |  subscribe-to-unlock-lite<br \/>\nSuper Store Finder |  superstorefinder-wp<br \/>\nSz\u00e9chenyi 2020 Logo |  szechenyi-2020-logo<br \/>\nT&#038;P Gallery Slider |  tp-gallery-slider<br \/>\nTableOn \u2013 WordPress Posts Table Filterable  |  posts-table-filterable<br \/>\nTarget Video Easy Publish |  brid-video-easy-publish<br \/>\nTaskbuilder \u2013 WordPress Project &#038; Task Management plugin |  taskbuilder<br \/>\nTeam Members \u2013 Best WordPress Team Plugin with Team Slider, Team Showcase &#038; Team Builder |  wps-team<br \/>\nTestimonial Slider And Showcase Pro |  testimonial-slider-showcase-pro<br \/>\nTheme Changer |  theme-changer<br \/>\nThemesflat Addons For Elementor |  themesflat-addons-for-elementor<br \/>\nThemify Shortcodes |  themify-shortcodes<br \/>\nTotal processing card payments for WooCommerce |  totalprocessing-card-payments<br \/>\nTour Master &#8211; Tour Booking, Travel, Hotel |  tourmaster<br \/>\nTourfic Toolkit |  travelfic-toolkit<br \/>\ntranslit it! |  translit-it<br \/>\nTS Poll \u2013 Survey, Versus Poll, Image Poll, Video Poll |  poll-wp<br \/>\nTuriTop Booking System |  turitop-booking-system<br \/>\nUix Shortcodes |  uix-shortcodes<br \/>\nUltimate Member \u2013 User Profile, Registration, Login, Member Directory, Content Restriction &#038; Membership Plugin |  ultimate-member<br \/>\nUltimate Store Kit \u2013 Elementor powered WooCommerce Builder, 80+ Widgets and Template Builder |  ultimate-store-kit<br \/>\nUnlimited Timeline |  unlimited-timeline<br \/>\nUrbanGo Membership |  urbango-membership<br \/>\nUser Profile Builder \u2013 Beautiful User Registration Forms, User Profiles &#038; User Role Editor |  profile-builder<br \/>\nUser Registration PRO \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin |  user-registration-pro<br \/>\nVerge3D Publishing and E-Commerce |  verge3d<br \/>\nVerowa Connect |  verowa-connect<br \/>\nvisucom-smart-sections |  visucom-smart-sections<br \/>\nVitepos \u2013 Point of sale (POS) plugin for WooCommerce |  vitepos-lite<br \/>\nWeb Directory Free |  web-directory-free<br \/>\nWooCommerce &#8211; Social Login |  woo-social-login<br \/>\nWooCommerce Builder &#038; Gutenberg WooCommerce Blocks \u2013 WowStore |  product-blocks<br \/>\nWooCommerce Products without featured images |  woocommerce-products-without-featured-images<br \/>\nWooMS |  wooms<br \/>\nWordPress Button Plugin MaxButtons |  maxbuttons<br \/>\nWordPress Internal Link Optimiser |  internal-link-finder<br \/>\nWordPress REST API Authentication |  wp-rest-api-authentication<br \/>\nWordPress Video Robot &#8211; The Ultimate Video Importer |  wp-video-robot<br \/>\nWordPress WP-Advanced-Search |  wp-advanced-search<br \/>\nWP Data Access \u2013 App, Table, Form, Chart &#038; Map Builder plugin |  wp-data-access<br \/>\nWP Donate |  wp-donate<br \/>\nWP Editor |  wp-editor<br \/>\nWP Flipclock |  wp-flipclock<br \/>\nWP Logger |  wp-data-logger<br \/>\nWP Post to PDF Enhanced |  wp-post-to-pdf-enhanced<br \/>\nWP Posts Carousel |  wp-posts-carousel<br \/>\nWP Simple Booking Calendar |  wp-simple-booking-calendar<br \/>\nWP Social Bookmarking |  wp-social-bookmarking<br \/>\nWP STAGING Pro WordPress Backup Plugin |  wp-staging-pro<br \/>\nWP Sticky Side Buttons |  wp-sticky-side-buttons<br \/>\nWP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log |  wptools<br \/>\nWP Twitter Button |  wp-twitter-button<br \/>\nwp-google-map-gold |  wp-google-map-gold<br \/>\nWP_DEBUG Toggle |  enable-wp-debug-toggle<br \/>\nWPAdverts \u2013 Classifieds Plugin |  wpadverts<br \/>\nWPAMS &#8211; Apartment Management System for wordpress |  apartment-management<br \/>\nWPCafe: Food Menu, Ordering, Reservation, and Delivery Solution \u2013 All in One Place! |  wp-cafe<br \/>\nWPCasa |  wpcasa<br \/>\nWPCOM Member |  wpcom-member<br \/>\nwpLike2Get |  wplike2get<br \/>\nwpt-whatsapp |  wpt-whatsapp<br \/>\nXelion Webchat |  xelion-webchat<br \/>\nZooEffect Plugin for Video player, Photo Gallery Slideshow jQuery and audio \/ music \/ podcast \u2013 HTML5 |  1-jquery-photo-gallery-slideshow-flash  <\/p>\n<p>* * *<\/p>\n<p>### WordPress Themes with Reported Vulnerabilities Last Week<\/p>\n<p>Software Name | Software Slug<br \/>\n&#8212;|&#8212;<br \/>\nAI Hub &#8211; Startup &#038; Technology WordPress Theme |  aihub<br \/>\nBetheme |  betheme<br \/>\nCelestial Aura |  celestial-aura<br \/>\nDessau &#8211; Contemporary Theme for Architects and Interior Designers |  dessau<br \/>\nD\u00f8r &#8211; Modern Architecture and Interior Design Theme |  dor<br \/>\nEduma |  eduma<br \/>\nEximius |  eximius<br \/>\nFoton &#8211; Software and App Landing Page Theme |  foton<br \/>\nGrand Restaurant WordPress |  grandrestaurant<br \/>\nGrip |  grip<br \/>\nIvyPrep &#8211; Education &#038; School WordPress Theme |  ivy-school<br \/>\nReal Estate 7 WordPress |  realestate-7<br \/>\nSirat |  sirat<br \/>\nTastyc &#8211; Cafe Restaurant Theme |  tastyc<br \/>\nWanderland &#8211; Travel Blog |  wanderland  <\/p>\n<p>* * *<\/p>\n<p>### Vulnerability Details<\/p>\n<p>Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should\u2019ve already been notified if your site was affected by any of these vulnerabilities. If you&#8217;d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.<\/p>\n<p>#### AIHub <= 1.3.7 - Unauthenticated Arbitrary File Upload in generate_image\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-1093**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nAI Hub - Startup &#038; Technology WordPress Theme\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/0c476cecff9cf0286378f2943694146f.jpg?s=32&#038;d=mp&#038;r=g)Foxyyy\n\nMore Details ><\/p>\n<p>#### Dessau < 1.9 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39463**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nDessau - Contemporary Theme for Architects and Interior Designers\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### Docket Cache <= 24.07.02 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39461**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nDocket Cache \u2013 Object Cache Accelerator\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f1b68a12f61846b7fbcd7f1338106a1f.jpg?s=32&#038;d=mp&#038;r=g)Dimas Maulana\n\nMore Details ><\/p>\n<p>#### D\u00f8r <= 2.4 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39466**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nD\u00f8r - Modern Architecture and Interior Design Theme\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### FluentBoards <= 1.47 - Unauthenticated PHP Object Injection\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39551**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nFluentBoards \u2013 Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### FluentCommunity <= 1.2.15 - Unauthenticated PHP Object Injection\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39550**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nFluentCommunity \u2013 Ultra-Fast High-Performance Social Network, Community, LMS &#038; Online Courses Plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### Foton <= 2.5.2 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39458**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nFoton - Software and App Landing Page Theme\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### Grip <= 1.0.9 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-26735**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nGrip\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)tahu.datar\n\nMore Details ><\/p>\n<p>#### HelpGent <= 2.2.4 - Unauthenticated PHP Object Injection\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-32658**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nHelpGent \u2013 The Ultimate Form Builder &#038; TypeForm Alternative on WordPress | Craft Conversational Multi Step Form with Video, Voice, Screen Recording, &#038; Text Messaging\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### hockeydata LOS <= 1.2.4 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-26889**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nhockeydata LOS\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f1b68a12f61846b7fbcd7f1338106a1f.jpg?s=32&#038;d=mp&#038;r=g)Dimas Maulana\n\nMore Details ><\/p>\n<p>#### Hotel Booking <= 3.6 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39526**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nHotel Booking\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### IvyPrep <= 1.6.0 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39470**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nIvyPrep - Education &#038; School WordPress Theme\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### JS Job Manager <= 2.0.2 - Unauthenticated Arbitrary File Upload\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-32660**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nJS Job Manager\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### Kata Plus <= 1.5.2 - Unauthenticated PHP Object Injection\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-32572**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nKata Plus \u2013 Addons for Elementor \u2013 Widgets, Extensions and Templates\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/385d41daf781fbf4dbac2a1ff894d7fc.jpg?s=32&#038;d=mp&#038;r=g)Le Ngoc Anh\n\nMore Details ><\/p>\n<p>#### Material Dashboard <= 1.4.6 - Unauthenticated Privilege Escalation\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-32486**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nMaterial Dashboard\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)astra.r3verii\n\nMore Details ><\/p>\n<p>#### Modal Survey <= 2.0.2.0.1 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39468**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nmodal-survey\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### Projectopia <= 5.1.16 - Unauthenticated Privilege Escalation via Account Takeover\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-32648**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nProjectopia \u2013 WordPress Project Management\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)astra.r3verii\n\nMore Details ><\/p>\n<p>#### Quentn WP <= 1.2.8 - Unauthenticated Privilege Escalation\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39596**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nQuentn WP\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/385d41daf781fbf4dbac2a1ff894d7fc.jpg?s=32&#038;d=mp&#038;r=g)Le Ngoc Anh\n\nMore Details ><\/p>\n<p>#### Real Estate 7 <= 3.5.2 - Unauthenticated Privilege Escalation\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39459**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nReal Estate 7 WordPress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Ananda Dhakal\n\nMore Details ><\/p>\n<p>#### Real Estate Manager <= 7.3 - Unauthenticated Remote Code Execution\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-32596**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nReal Estate Manager \u2013 Property Listing and Agent Management\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/01dce303f1fab51371215f21992679d9.jpg?s=32&#038;d=mp&#038;r=g)theviper17y\n\nMore Details ><\/p>\n<p>#### Smart Agreements <= 1.0.3 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39462**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nSmart Agreements\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f1b68a12f61846b7fbcd7f1338106a1f.jpg?s=32&#038;d=mp&#038;r=g)Dimas Maulana\n\nMore Details ><\/p>\n<p>#### Smart Sections Theme Builder &#8211; WPBakery Page Builder Addon <= 1.7.8 - Unauthenticated PHP Object Injection\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39410**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nvisucom-smart-sections\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### Sz\u00e9chenyi 2020 Logo <= 1.1 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39429**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nSz\u00e9chenyi 2020 Logo\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### Tastyc < 2.5.2 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-27010**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nTastyc - Cafe Restaurant Theme\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### Ultimate Store Kit Elementor Addons <= 2.4.0 - Unauthenticated PHP Object Injection\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39588**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nUltimate Store Kit \u2013 Elementor powered WooCommerce Builder, 80+ Widgets and Template Builder\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)domiee13\n\nMore Details ><\/p>\n<p>#### UrbanGo Membership <= 1.0.4 - Unauthenticated Privilege Escalation\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-3278**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nUrbanGo Membership\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2b99835f57008d2a5ee94f41555327d4.jpg?s=32&#038;d=mp&#038;r=g)Alyudin Nafiie\n\nMore Details ><\/p>\n<p>#### Wanderland <= 1.7.1 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39467**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWanderland - Travel Blog\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### WhatsApp Click to Chat Plugin for WordPress <= 2.2.12 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39411**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nwpt-whatsapp\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### WPAMS <= 44.0 - Unauthenticated Local File Inclusion\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39406**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWPAMS - Apartment Management System for wordpress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/11dfabc58a06f06c9123a7e17a41cecb.jpg?s=32&#038;d=mp&#038;r=g)Aiden (Th\u00e1i An)\n\nMore Details ><\/p>\n<p>#### WPAMS <= 44.0 (17-08-2023) - Unauthenticated Arbitrary File Upload\n\n9.8\n\nCVSS Rating  \n**Critical (9.8)**\n\nCVE-ID  \n**CVE-2025-39401**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWPAMS - Apartment Management System for wordpress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### Celestial Aura <= 2.2 - Authenticated (Subscriber+) Arbitrary File Upload\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-26892**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nCelestial Aura\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### Custom CSS, JS &#038; PHP <= 2.4.1 - Cross-Site Request Forgery to Remote Code Exectuiron\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39601**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nCustom CSS, JS &#038; PHP\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-3404**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nDownload Manager\n\n**Researchers**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/c070414ac7706c1f7345b025f413df56.jpg?s=32&#038;d=mp&#038;r=g)Brian Sans-Souci (liardom)\n\n![](https:\/\/www.gravatar.com\/avatar\/5a1c57ff7dc66a0d8702f856ceb355fd.jpg?s=32&#038;d=mp&#038;r=g)the sneaky squirrel\n\nMore Details ><\/p>\n<p>#### Eventin <= 4.0.25 - Authenticated (Contributor+) Local File Inclusion\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39584**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nEvent Manager, Events Calendar, Tickets, Registrations \u2013 Eventin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/01dce303f1fab51371215f21992679d9.jpg?s=32&#038;d=mp&#038;r=g)theviper17y\n\nMore Details ><\/p>\n<p>#### Eximius <= 2.2 - Authenticated (Subscriber+) Arbitrary File Upload\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-26872**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nEximius\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### I Draw <= 1.0 - Authenticated (Author+) Arbitrary File Upload\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39436**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nI Draw\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### JetReviews <= 2.3.6 - Authenticated (Contributor+) Local File Inclusion\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39396**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nJetReviews for Elementor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### MapSVG Lite <= 8.5.34 - Authenticated (Contributor+) Arbitrary File Upload\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-32682**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nMapSVG \u2013 Vector maps, Image maps, Google Maps\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/54d48d97cbd2b84eb914943109eb7d14.jpg?s=32&#038;d=mp&#038;r=g)Nguy\u1ec5n Trung Ki\u00ean\n\nMore Details ><\/p>\n<p>#### PDF 2 Post <= 2.4.0 - Authenticated (Subscriber+) Remote Code Execution\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-32583**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nPDF 2 Post\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/385d41daf781fbf4dbac2a1ff894d7fc.jpg?s=32&#038;d=mp&#038;r=g)Le Ngoc Anh\n\nMore Details ><\/p>\n<p>#### Question Answer <= 1.2.70 - Authenticated (Subscriber+) PHP Object Injection\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-32647**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nQuestion Answer\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### Rating by BestWebSoft <= 1.7 - Authenticated (Subscriber+) PHP Object Injection\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39527**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nRating by BestWebSoft\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/385d41daf781fbf4dbac2a1ff894d7fc.jpg?s=32&#038;d=mp&#038;r=g)Le Ngoc Anh\n\nMore Details ><\/p>\n<p>#### Starfish Review Generation &#038; Marketing <= 3.1.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39533**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nStarfish Review Generation &#038; Marketing for WordPress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### Subscribe to Unlock Lite <= 1.3.0 - Authenticated (Contributor+) Local File Inclusion\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39592**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nSubscribe to Unlock Lite \u2013 Opt In Content Locker Plugin for WordPress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### Team Members <= 3.4.1 - Authenticated (Contributor+) PHP Object Injection\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-32686**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nTeam Members \u2013 Best WordPress Team Plugin with Team Slider, Team Showcase &#038; Team Builder\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/7b8cd550e860295a0dcf86632e3c79be.jpg?s=32&#038;d=mp&#038;r=g)Phat RiO - BlueRock\n\nMore Details ><\/p>\n<p>#### Testimonial Slider And Showcase Pro <= 2.1.7 - Authenticated (Subscriber+) Local File Inclusion\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-32657**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nTestimonial Slider And Showcase Pro\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### TuriTop Booking System <= 1.0.10 - Authenticated (Subscriber+) PHP Object Injection\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-32571**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nTuriTop Booking System\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### uListing <= 2.2.0 - Authenticated (Subscriber+) PHP Object Injection\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-32662**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nDirectory Listings WordPress plugin \u2013 uListing\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/7b8cd550e860295a0dcf86632e3c79be.jpg?s=32&#038;d=mp&#038;r=g)Phat RiO - BlueRock\n\nMore Details ><\/p>\n<p>#### WPAMS <= 44.0 (17-08-2023) - Authenticated (Subscriber+) Arbitrary File Upload\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39402**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWPAMS - Apartment Management System for wordpress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### WPAMS <= 44.0 (17-08-2023) - Authenticated (Subscriber+) Privilege Escalation\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39405**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWPAMS - Apartment Management System for wordpress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/11dfabc58a06f06c9123a7e17a41cecb.jpg?s=32&#038;d=mp&#038;r=g)Aiden (Th\u00e1i An)\n\nMore Details ><\/p>\n<p>#### WPCafe <= 2.2.32 - Authenticated (Contributor+) Local File Inclusion\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39452**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWPCafe: Food Menu, Ordering, Reservation, and Delivery Solution \u2013 All in One Place!\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/01dce303f1fab51371215f21992679d9.jpg?s=32&#038;d=mp&#038;r=g)theviper17y\n\nMore Details ><\/p>\n<p>#### WPCOM Member <= 1.7.7 - Authenticated (Contributor+) Local File Inclusion\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39570**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWPCOM Member\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)astra.r3verii\n\nMore Details ><\/p>\n<p>#### Xelion Webchat <= 9.1.0 - Authenticated (Subscriber+) Privilege Escalation\n\n8.8\n\nCVSS Rating  \n**High (8.8)**\n\nCVE-ID  \n**CVE-2025-39542**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nXelion Webchat\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### Avatar <= 0.1.4 - Authenticated (Subscriber+) Arbitrary File Deletion\n\n8.1\n\nCVSS Rating  \n**High (8.1)**\n\nCVE-ID  \n**CVE-2025-3520**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nAvatar\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/01dce303f1fab51371215f21992679d9.jpg?s=32&#038;d=mp&#038;r=g)theviper17y\n\nMore Details ><\/p>\n<p>#### CLEVER &#8211; HTML5 Radio Player With History &#8211; Shoutcast and Icecast &#8211; Elementor Widget Addon <= 2.4 - Unauthenticated Arbitrary File Read\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-3103**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nCLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/9d46e040922297c1834a9af4e8278abe.jpg?s=32&#038;d=mp&#038;r=g)khanhhnahk1\n\nMore Details ><\/p>\n<p>#### Cost Calculator Builder <= 3.2.65 - Unauthenticated SQL Injection\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-39587**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nCost Calculator Builder\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### JobWP \u2013 Job Board, Job Listing, Career Page and Recruitment Plugin <= 2.3.9 - Unauthenticated SQL Injection\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-2010**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nJobWP \u2013 Job Board, Job Listing, Career Page and Recruitment Plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### JS Job Manager <= 2.0.2 - Unauthenticated SQL Injection\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-32626**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nJS Job Manager\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### Local Magic <= 2.6.0 - Unauthenticated SQL Injection\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-32636**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nLocal Magic\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### Modal Survey <= 2.0.2.0.1 - Unauthenticated SQL Injection\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-39471**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nmodal-survey\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### Office Locator <= 1.3.0 - Unauthenticated SQL Injection\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-32665**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nOffice Locator\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### Quentn WP <= 1.2.8 - Unauthenticated SQL Injection\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-39595**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nQuentn WP\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/385d41daf781fbf4dbac2a1ff894d7fc.jpg?s=32&#038;d=mp&#038;r=g)Le Ngoc Anh\n\nMore Details ><\/p>\n<p>#### StoreContrl Woocommerce <= 4.1.3 - Unauthenticated Arbitrary File Download\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-39568**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nStoreContrl Woocommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)astra.r3verii\n\nMore Details ><\/p>\n<p>#### Super Store Finder <= 7.2 - Unauthenticated SQL Injection\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-39445**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nSuper Store Finder\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/54d48d97cbd2b84eb914943109eb7d14.jpg?s=32&#038;d=mp&#038;r=g)Nguy\u1ec5n Trung Ki\u00ean\n\nMore Details ><\/p>\n<p>#### Ultimate Member \u2013 User Profile, Registration, Login, Member Directory, Content Restriction &#038; Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**Unknown**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nUltimate Member \u2013 User Profile, Registration, Login, Member Directory, Content Restriction &#038; Membership Plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/faefcd06abcb00b4db5324b629c6424e.jpg?s=32&#038;d=mp&#038;r=g)Muhamad Visat\n\nMore Details ><\/p>\n<p>#### WP Headers And Footers <= 3.1.1 - Cross-Site Request Forgery to Arbitrary Options Update\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-2111**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nInsert Headers And Footers\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/80711f5dab8609bebef4ab99b37e869a.jpg?s=32&#038;d=mp&#038;r=g)Carlos Ferreira\n\nMore Details ><\/p>\n<p>#### WPAMS <= 44.0 (17-08-2023) - Unauthenticated SQL Injection\n\n7.5\n\nCVSS Rating  \n**High (7.5)**\n\nCVE-ID  \n**CVE-2025-39395**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWPAMS - Apartment Management System for wordpress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/11dfabc58a06f06c9123a7e17a41cecb.jpg?s=32&#038;d=mp&#038;r=g)Aiden (Th\u00e1i An)\n\nMore Details ><\/p>\n<p>#### Debug Log Manager <= 2.3.4 - Unauthenticated Stored Cross-Site Scripting\n\n7.2\n\nCVSS Rating  \n**High (7.2)**\n\nCVE-ID  \n**CVE-2025-3809**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nDebug Log Manager\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/1c6327bca62253f0bec06a3d18c37f2a.jpg?s=32&#038;d=mp&#038;r=g)Yassine Neggaoui (Y45NG)\n\nMore Details ><\/p>\n<p>#### Kadence WooCommerce Email Designer <= 1.5.14 - Authenticated (Admin+) Arbitrary File Upload\n\n7.2\n\nCVSS Rating  \n**High (7.2)**\n\nCVE-ID  \n**CVE-2025-39557**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nKadence WooCommerce Email Designer\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Phan Trong Quan\n\nMore Details ><\/p>\n<p>#### MelaPress Login Security <= 2.1.0 - Authenticated (Administrator+) PHP Object Injection\n\n7.2\n\nCVSS Rating  \n**High (7.2)**\n\nCVE-ID  \n**CVE-2025-39565**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nMelaPress Login Security\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Phan Trong Quan\n\nMore Details ><\/p>\n<p>#### T&#038;P Gallery Slider <= 1.2 - Unauthenticated Stored Cross-Site Scripting\n\n7.2\n\nCVSS Rating  \n**High (7.2)**\n\nCVE-ID  \n**CVE-2025-32527**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nT&#038;P Gallery Slider\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/b5bd58d8a8029c69877dc8a75d7889fd.jpg?s=32&#038;d=mp&#038;r=g)K\u00e9vin Mosbahi (Mika)\n\nMore Details ><\/p>\n<p>#### WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Update\n\n7.2\n\nCVSS Rating  \n**High (7.2)**\n\nCVE-ID  \n**CVE-2025-3294**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWP Editor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/37cc74b0e1957fee81825154abeae540.jpg?s=32&#038;d=mp&#038;r=g)nquangit\n\nMore Details ><\/p>\n<p>#### WP-Advanced-Search <= 3.3.9.3 - Authenticated (Admin+) Arbitrary File Upload\n\n7.2\n\nCVSS Rating  \n**High (7.2)**\n\nCVE-ID  \n**CVE-2025-39538**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWordPress WP-Advanced-Search\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&#038;d=mp&#038;r=g)Nabil Irawan\n\nMore Details ><\/p>\n<p>#### Editor Wysiwyg Background Color <= 1.0 - Missing Authorization\n\n6.5\n\nCVSS Rating  \n**Medium (6.5)**\n\nCVE-ID  \n**CVE-2025-23958**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nEditor Wysiwyg Background Color\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/b5bd58d8a8029c69877dc8a75d7889fd.jpg?s=32&#038;d=mp&#038;r=g)K\u00e9vin Mosbahi (Mika)\n\nMore Details ><\/p>\n<p>#### KiotViet Sync <= 1.8.3 - Authenticated (Subscriber+) SQL Injection\n\n6.5\n\nCVSS Rating  \n**Medium (6.5)**\n\nCVE-ID  \n**CVE-2025-32573**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nKiotViet Sync\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/385d41daf781fbf4dbac2a1ff894d7fc.jpg?s=32&#038;d=mp&#038;r=g)Le Ngoc Anh\n\nMore Details ><\/p>\n<p>#### ProfileGrid <= 5.9.4.8 - Authenticated (Subscriber+) SQL Injection\n\n6.5\n\nCVSS Rating  \n**Medium (6.5)**\n\nCVE-ID  \n**CVE-2025-39586**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nProfileGrid \u2013 User Profiles, Groups and Communities\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### Sign-up Sheets <= 2.3.0.1 - Unauthenticated Arbitrary Shortcode Execution\n\n6.5\n\nCVSS Rating  \n**Medium (6.5)**\n\nCVE-ID  \n**CVE-2025-26996**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nSign-up Sheets\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Phan Trong Quan\n\nMore Details ><\/p>\n<p>#### Taskbuilder <= 4.0.1 - Authenticated (Subscriber+) SQL Injection\n\n6.5\n\nCVSS Rating  \n**Medium (6.5)**\n\nCVE-ID  \n**CVE-2025-39569**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nTaskbuilder \u2013 WordPress Project &#038; Task Management plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)astra.r3verii\n\nMore Details ><\/p>\n<p>#### WP Tools <= 5.18 - Cross-Site Request Forgery to Arbitrary File Renaming\n\n6.5\n\nCVSS Rating  \n**Medium (6.5)**\n\nCVE-ID  \n**CVE-2025-39544**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)chuck\n\nMore Details ><\/p>\n<p>#### WPAMS <= 44.0 (17-08-2023) - Authenticated (Subscriber+) SQL Injection\n\n6.5\n\nCVSS Rating  \n**Medium (6.5)**\n\nCVE-ID  \n**CVE-2025-39403**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWPAMS - Apartment Management System for wordpress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/11dfabc58a06f06c9123a7e17a41cecb.jpg?s=32&#038;d=mp&#038;r=g)Aiden (Th\u00e1i An)\n\nMore Details ><\/p>\n<p>#### Asgaros Forum <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39514**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nAsgaros Forum\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Attendance Manager <= 0.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39515**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nAttendance Manager\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Author WIP Progress Bar <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39516**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nAuthor WIP Progress Bar\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Betheme <= 28.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-3077**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nBetheme\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/ef74f4dbe7907a62f177592f647c1afa.jpg?s=32&#038;d=mp&#038;r=g)Webbernaut\n\nMore Details ><\/p>\n<p>#### Checkout Files Upload for WooCommerce <= 2.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39520**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nCheckout Files Upload for WooCommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Checkout for PayPal <= 1.0.38 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39572**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nCheckout for PayPal\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Church Admin <= 5.0.23 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39555**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nChurch Admin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/4c2bd6964b38518385c4e8d1791fd762.jpg?s=32&#038;d=mp&#038;r=g)zaim\n\nMore Details ><\/p>\n<p>#### Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.28 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-1457**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nElement Pack Addons for Elementor \u2013 Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/ef74f4dbe7907a62f177592f647c1afa.jpg?s=32&#038;d=mp&#038;r=g)Webbernaut\n\nMore Details ><\/p>\n<p>#### Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39590**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nEssential Addons for Elementor \u2013 Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits &#038; WooCommerce Builders\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-3615**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nFluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, &#038; Conversational Form Builder\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e4a8b174c9f284d94094cf7722e1ec31.jpg?s=32&#038;d=mp&#038;r=g)Asaf Mozes\n\nMore Details ><\/p>\n<p>#### Forminator <= 1.42.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit'\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-3487**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nForminator Forms \u2013 Contact Form, Payment Form &#038; Custom Form Builder\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e4a8b174c9f284d94094cf7722e1ec31.jpg?s=32&#038;d=mp&#038;r=g)Asaf Mozes\n\nMore Details ><\/p>\n<p>#### Html5 Audio Player <= 2.2.28 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39524**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nHTML5 Audio Player- Best WordPress Audio Player Plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### JetElements For Elementor <= 2.7.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39448**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nJetElements\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### JetTabs <= 2.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39450**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nJetTabs for Elementor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### LA-Studio Element Kit for Elementor <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-3106**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nLA-Studio Element Kit for Elementor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/ef74f4dbe7907a62f177592f647c1afa.jpg?s=32&#038;d=mp&#038;r=g)Webbernaut\n\nMore Details ><\/p>\n<p>#### Logo Carousel Gutenberg Block <= 2.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via sliderId Parameter\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-2083**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nLogo Carousel Gutenberg Block\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/258c774aecd81b7d1fa67abf3b576b33.jpg?s=32&#038;d=mp&#038;r=g)Peter Thaleikis\n\nMore Details ><\/p>\n<p>#### Logo Carousel Slider <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39525**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nLogo Carousel Slider\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Membership For WooCommerce <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39579**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nMembership For WooCommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/4c2bd6964b38518385c4e8d1791fd762.jpg?s=32&#038;d=mp&#038;r=g)zaim\n\nMore Details ><\/p>\n<p>#### Most And Least Read Posts Widget <= 2.5.20 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39549**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nMost And Least Read Posts Widget\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Piotnet Addons For Elementor <= 2.4.34 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2024-13650**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nPiotnet Addons For Elementor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/a964068aac6d7229783a0ea643877251.jpg?s=32&#038;d=mp&#038;r=g)zer0gh0st\n\nMore Details ><\/p>\n<p>#### PropertyHive <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39577**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nProperty Hive\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Rescue Shortcodes <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39528**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nRescue Shortcodes\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Responsive Addons for Elementor \u2013 Free Elementor Addons Plugin and Elementor Templates <= 1.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'rael_title_tag'\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-2225**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nResponsive Addons for Elementor \u2013 Free Elementor Addons Plugin and Elementor Templates\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/eb428a7b41bcec038cb1bd520e1bc384.jpg?s=32&#038;d=mp&#038;r=g)Prissy\n\nMore Details ><\/p>\n<p>#### Responsive Blocks <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39578**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nResponsive Blocks \u2013 WordPress Gutenberg Blocks\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/4c2bd6964b38518385c4e8d1791fd762.jpg?s=32&#038;d=mp&#038;r=g)zaim\n\nMore Details ><\/p>\n<p>#### Royal Elementor Addons <= 1.3.977 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39543**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nRoyal Elementor Addons and Templates\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### SB Chart block <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via className Parameter\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-3661**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nSB Chart block\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/258c774aecd81b7d1fa67abf3b576b33.jpg?s=32&#038;d=mp&#038;r=g)Peter Thaleikis\n\nMore Details ><\/p>\n<p>#### Scriptless Social Sharing <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39529**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nScriptless Social Sharing\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Themesflat Addons For Elementor <= 2.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-3275**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nThemesflat Addons For Elementor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/ef74f4dbe7907a62f177592f647c1afa.jpg?s=32&#038;d=mp&#038;r=g)Webbernaut\n\nMore Details ><\/p>\n<p>#### Themify Shortcodes <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39581**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nThemify Shortcodes\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/258c774aecd81b7d1fa67abf3b576b33.jpg?s=32&#038;d=mp&#038;r=g)Peter Thaleikis\n\nMore Details ><\/p>\n<p>#### Travelfic Toolkit <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39585**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nTourfic Toolkit\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&#038;d=mp&#038;r=g)Jo\u00e3o Pedro Soares de Alc\u00e2ntara\n\nMore Details ><\/p>\n<p>#### Uix Shortcodes <= 2.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39574**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nUix Shortcodes\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles &#038; User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-2314**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nUser Profile Builder \u2013 Beautiful User Registration Forms, User Profiles &#038; User Role Editor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### WP Data Access <= 5.5.36 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39582**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWP Data Access \u2013 App, Table, Form, Chart &#038; Map Builder plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/258c774aecd81b7d1fa67abf3b576b33.jpg?s=32&#038;d=mp&#038;r=g)Peter Thaleikis\n\nMore Details ><\/p>\n<p>#### WP Flipclock <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39540**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWP Flipclock\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/01dce303f1fab51371215f21992679d9.jpg?s=32&#038;d=mp&#038;r=g)theviper17y\n\nMore Details ><\/p>\n<p>#### WP Posts Carousel <= 1.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39573**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWP Posts Carousel\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### WPAdverts <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39576**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWPAdverts \u2013 Classifieds Plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### WPCasa <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n\n6.4\n\nCVSS Rating  \n**Medium (6.4)**\n\nCVE-ID  \n**CVE-2025-39575**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWPCasa\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Add to Header <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39423**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nAdd to Header\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### AdminQuickbar <= 1.9.1 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39464**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nAdminQuickbar\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f1b68a12f61846b7fbcd7f1338106a1f.jpg?s=32&#038;d=mp&#038;r=g)Dimas Maulana\n\nMore Details ><\/p>\n<p>#### All push notification for WP <= 1.5.3 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32546**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nAll push notification for WP\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g)0xd4rk5id3\n\nMore Details ><\/p>\n<p>#### Amazon Showcase WordPress Plugin <= 2.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39431**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nAmazon Showcase WordPress Plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### Arigato Autoresponder and Newsletter <= 2.7.2.4 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39594**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nArigato Autoresponder and Newsletter\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/385d41daf781fbf4dbac2a1ff894d7fc.jpg?s=32&#038;d=mp&#038;r=g)Le Ngoc Anh\n\nMore Details ><\/p>\n<p>#### Booster Plus for WooCommerce <= 7.2.4 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39446**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nBooster Plus for WooCommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### Broken Links Remover <= 1.2.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39440**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nBroken Links Remover\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### BruteGuard \u2013 Brute Force Login Protection <= 0.1.4 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39408**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nBruteGuard \u2013 Brute Force Login Protection\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g)0xd4rk5id3\n\nMore Details ><\/p>\n<p>#### Bulk Page Stub Creator <= 1.1 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39519**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nBulk Page Stub Creator\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### Contact Form by Supsystic <= 1.7.29 - Cross-Site Request Forgery to Stored Cross-Site Scripting via saveAsCopy AJAX Action\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2024-13452**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nContact Form by Supsystic\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/b20f9553188fa04cbd937e5df1e718af.jpg?s=32&#038;d=mp&#038;r=g)Tim Coen\n\nMore Details ><\/p>\n<p>#### Contact Form vCard Generator <= 2.4 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39521**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nContact Form vCard Generator\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### Coupon Affiliates \u2013 Affiliate Plugin for WooCommerce <= 6.3.0 - Reflected Cross-Site Scripting via 'commission_summary' Parameter\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-3598**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nCoupon Affiliates \u2013 Affiliate Plugin for WooCommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/14c9ac0f163cbf6d8b0f77fce5836577.jpg?s=32&#038;d=mp&#038;r=g)wesley (wcraft)\n\nMore Details ><\/p>\n<p>#### Course Booking System <= 6.1 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32508**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nCourse Booking System\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### CRM Perks <= 1.1.7 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39558**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nCRM Perks \u2013 WordPress HelpDesk Integration \u2013 Zendesk, Freshdesk, HelpScout\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g)0xd4rk5id3\n\nMore Details ><\/p>\n<p>#### CRUDLab Scroll to Top <= 1.0.1 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-22774**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nCRUDLab Scroll to Top\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&#038;d=mp&#038;r=g)Jo\u00e3o Pedro Soares de Alc\u00e2ntara\n\nMore Details ><\/p>\n<p>#### Dashboard Notepads <= 1.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39441**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nDashboard Notepads\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### Event Espresso \u2013 Custom Email Template Shortcode <= 1.0.0 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32507**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nEvent Espresso \u2013 Custom Email Template Shortcode\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&#038;d=mp&#038;r=g)Jo\u00e3o Pedro Soares de Alc\u00e2ntara\n\nMore Details ><\/p>\n<p>#### Fast eBay Listings <= 2.12.15 - Open Redirect\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39597**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nFast eBay Listings\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### Feedify \u2013 Web Push Notifications <= 2.4.5 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32540**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nFeedify \u2013 Web Push Notifications\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&#038;d=mp&#038;r=g)Jo\u00e3o Pedro Soares de Alc\u00e2ntara\n\nMore Details ><\/p>\n<p>#### GoodBarber <= 1.0.26 - Open Redirect\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39523**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nGoodBarber\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/385d41daf781fbf4dbac2a1ff894d7fc.jpg?s=32&#038;d=mp&#038;r=g)Le Ngoc Anh\n\nMore Details ><\/p>\n<p>#### Hive Support <= 1.2.2 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32666**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nHive Support | AI-Powered Help Desk, Live Chat &#038; AI Chat Bot Plugin for WordPress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### Internal Link Optimiser <= 5.1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39547**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWordPress Internal Link Optimiser\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### KiotViet Sync <= 1.8.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39381**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nKiotViet Sync\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### Landing Page Cat <= 1.7.8 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-26992**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nLanding Page Cat \u2013 Coming Soon Page, Maintenance Page &#038; Squeeze Pages\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### Listdom <= 4.0.0 - Open Redirect\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39599**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nListdom \u2013 Business Directory and Classified Ads Listings WordPress Plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### Memberpress <= 1.11.37 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39407**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nMemberpress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g)0xd4rk5id3\n\nMore Details ><\/p>\n<p>#### MemberPress Discord Addon <= 1.1.1 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32605**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nSell access, Automate, and add Engaging Exclusive Discord Access: Introducing the MemberPress Discord Addon \u2014 Elevate Your Community!\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g)0xd4rk5id3\n\nMore Details ><\/p>\n<p>#### Modal Survey <= 2.0.2.0.1 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39469**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nmodal-survey\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### Movylo Marketing Automation <= 2.0.7 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32608**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nMovylo Marketing Automation\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g)0xd4rk5id3\n\nMore Details ><\/p>\n<p>#### My Marginalia <= 1.0.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39435**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nMy Marginalia\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### Nomupay Payment Processing Gateway <= 7.1.6 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32513**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nTotal processing card payments for WooCommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&#038;d=mp&#038;r=g)Jo\u00e3o Pedro Soares de Alc\u00e2ntara\n\nMore Details ><\/p>\n<p>#### OTP-less one tap Sign in <= 2.0.58 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32622**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nOTP-less one tap Sign in\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g)0xd4rk5id3\n\nMore Details ><\/p>\n<p>#### Revision Diet <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39419**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nRevision Diet\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### Right Click Disable OR Ban <= 1.1.17 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39548**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nRight Click Disable OR Ban\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### RSS Manager <= 0.06 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39418**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nRSS Manager\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### Run Contests, Raffles, and Giveaways with ContestsWP <= 2.0.6 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32634**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nRun Contests, Raffles, and Giveaways with ContestsWP\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&#038;d=mp&#038;r=g)Jo\u00e3o Pedro Soares de Alc\u00e2ntara\n\nMore Details ><\/p>\n<p>#### Sassy Social Share <= 3.3.73 - Open Redirect\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39404**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nSocial Sharing Plugin \u2013 Sassy Social Share\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Affan Ali\n\nMore Details ><\/p>\n<p>#### ShopApper <= 0.4.39 - Unauthenticated Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32638**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nShopApper: Mobile App for WooCommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### Site Search 360 <= 2.1.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39530**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nSite Search 360\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### Social Media Links <= 1.0.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39415**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nSocial Media Links\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### spam-stopper <= 3.1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39414**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nspam-stopper\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### TableOn \u2013 WordPress Posts Table Filterable <= 1.0.3 - Unauthenticated Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32592**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nTableOn \u2013 WordPress Posts Table Filterable \n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Abdi Pranata\n\nMore Details ><\/p>\n<p>#### Tourmaster < 5.4.1 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32923**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nTour Master - Tour Booking, Travel, Hotel\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### translit it! <= 1.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39416**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \ntranslit it!\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### Verowa Connect <= 3.0.4 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32609**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nVerowa Connect\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g)0xd4rk5id3\n\nMore Details ><\/p>\n<p>#### Web Directory Free <= 1.7.8 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39567**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWeb Directory Free\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)astra.r3verii\n\nMore Details ><\/p>\n<p>#### WooMS <= 9.12 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32602**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nWooMS\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g)0xd4rk5id3\n\nMore Details ><\/p>\n<p>#### WordPress Video Robot &#8211; The Ultimate Video Importer <= 1.20.0 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39409**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWordPress Video Robot - The Ultimate Video Importer\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Bonds\n\nMore Details ><\/p>\n<p>#### WP Donate <= 2.0 - Unauthenticated Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32637**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nWP Donate\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### WP_DEBUG Toggle <= 1.1 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-32561**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nWP_DEBUG Toggle\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/c14731a0f8a0d24cbda30f561fc03441.jpg?s=32&#038;d=mp&#038;r=g)SOPROBRO\n\nMore Details ><\/p>\n<p>#### WPAMS <= 44.0 (17-08-2023) - Unauthenticated Stored Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-39392**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWPAMS - Apartment Management System for wordpress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/11dfabc58a06f06c9123a7e17a41cecb.jpg?s=32&#038;d=mp&#038;r=g)Aiden (Th\u00e1i An)\n\nMore Details ><\/p>\n<p>#### ZooEffect <= 1.11 - Reflected Cross-Site Scripting\n\n6.1\n\nCVSS Rating  \n**Medium (6.1)**\n\nCVE-ID  \n**CVE-2025-26954**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nZooEffect Plugin for Video player, Photo Gallery Slideshow jQuery and audio \/ music \/ podcast \u2013 HTML5\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f1b68a12f61846b7fbcd7f1338106a1f.jpg?s=32&#038;d=mp&#038;r=g)Dimas Maulana\n\nMore Details ><\/p>\n<p>#### Gravity Forms CSS Themes with Fontawesome and Placeholders <= 8.5 - Authenticated (Administrator+) Stored Cross-Site Scripting\n\n5.5\n\nCVSS Rating  \n**Medium (5.5)**\n\nCVE-ID  \n**CVE-2025-39428**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nGravity Forms CSS Themes with Fontawesome and Placeholders\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&#038;d=mp&#038;r=g)Nabil Irawan\n\nMore Details ><\/p>\n<p>#### Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload\n\n5.4\n\nCVSS Rating  \n**Medium (5.4)**\n\nCVE-ID  \n**CVE-2025-3056**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nDownload Manager\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/4c8e47602daa5f66a49fdf2c7555c730.jpg?s=32&#038;d=mp&#038;r=g)siavashvafshar\n\nMore Details ><\/p>\n<p>#### Target Video Easy Publish <= 3.8.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution\n\n5.4\n\nCVSS Rating  \n**Medium (5.4)**\n\nCVE-ID  \n**CVE-2025-32688**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nTarget Video Easy Publish\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Phan Trong Quan\n\nMore Details ><\/p>\n<p>#### ActiveDEMAND <= 0.2.46 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39513**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nActiveDEMAND\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### AI Text to Speech <= 3.0.3 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39554**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nAI Text to Speech \u2013 TTS Plugin For WordPress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/b5bd58d8a8029c69877dc8a75d7889fd.jpg?s=32&#038;d=mp&#038;r=g)K\u00e9vin Mosbahi (Mika)\n\nMore Details ><\/p>\n<p>#### AnalyticsWP <= 2.0.0 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39388**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nAnalyticsWP\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### AnalyticsWP <= 2.1.2 - Unauthenticated Sensitive Information Exposure\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39394**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nAnalyticsWP\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### Booking and Rental Manager <= 2.2.8 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39457**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nBooking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### Booking and Rental Manager <= 2.3.8 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39390**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nBooking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)LVT-tholv2k\n\nMore Details ><\/p>\n<p>#### Church Admin <= 5.0.9 - Unauthenticated Information Disclosure\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39553**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nChurch Admin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/b5bd58d8a8029c69877dc8a75d7889fd.jpg?s=32&#038;d=mp&#038;r=g)K\u00e9vin Mosbahi (Mika)\n\nMore Details ><\/p>\n<p>#### Cloak Front End Email <= 1.9.5 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-26968**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nCloak Front End Email\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&#038;d=mp&#038;r=g)muhammad yudha\n\nMore Details ><\/p>\n<p>#### Contact Form 7 <= 6.0.5 - Order Replay Vulnerability\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-3247**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nContact Form 7\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e4a8b174c9f284d94094cf7722e1ec31.jpg?s=32&#038;d=mp&#038;r=g)Asaf Mozes\n\nMore Details ><\/p>\n<p>#### Dashi <= 3.1.8 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39580**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nDashi\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g)0xd4rk5id3\n\nMore Details ><\/p>\n<p>#### Eduma <= 5.6.4 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39460**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nEduma\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Ananda Dhakal\n\nMore Details ><\/p>\n<p>#### Forminator <= 1.42.0 - Order Replay Vulnerability\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-3479**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nForminator Forms \u2013 Contact Form, Payment Form &#038; Custom Form Builder\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e4a8b174c9f284d94094cf7722e1ec31.jpg?s=32&#038;d=mp&#038;r=g)Asaf Mozes\n\nMore Details ><\/p>\n<p>#### Grand Restaurant WordPress <= 7.0 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39353**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nGrand Restaurant WordPress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Ananda Dhakal\n\nMore Details ><\/p>\n<p>#### Hive Support <= 1.2.2 - Unauthenticated Sensitive Information Exposure\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-32635**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nHive Support | AI-Powered Help Desk, Live Chat &#038; AI Chat Bot Plugin for WordPress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### JetBlocks For Elementor <= 1.3.16 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39451**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nJetBlocks for Elementor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### JetBlog <= 2.4.3 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-26958**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nJetBlog for Elementor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### JetElements For Elementor <= 2.7.4.1 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39447**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nJetElements\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### JetMenu <= 2.4.9 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-26953**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nJetMenu for Elementor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### JetPopup <= 2.0.11 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-26944**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nJetPopup\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### JetTricks <= 1.5.1 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-26942**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nJetTricks for Elementor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### JetWooBuilder <= 2.1.18 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39449**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nJetWooBuilder for Elementor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### Macro Calculator with Admin Email Optin &#038; Data <= 1.0 - Unauthenticated Information Disclosure\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-26730**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nMacro Calculator with Admin Email Optin &#038; Data\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Deltree\n\nMore Details ><\/p>\n<p>#### Mediavine Control Panel <= 2.10.6 - Unauthenticated Information Exposure\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39556**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nMediavine Control Panel\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/54d48d97cbd2b84eb914943109eb7d14.jpg?s=32&#038;d=mp&#038;r=g)Nguy\u1ec5n Trung Ki\u00ean\n\nMore Details ><\/p>\n<p>#### Password Protected \u2013 Password Protect your WordPress Site, Pages, &#038; WooCommerce Products <= 2.7.7 - Unauthenticated Sensitive Information Exposure\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-3453**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nPassword Protected \u2013 Password Protect your WordPress Site, Pages, &#038; WooCommerce Products \u2013 Restrict Content, Protect WooCommerce Category and more\n\n**Researchers**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/c070414ac7706c1f7345b025f413df56.jpg?s=32&#038;d=mp&#038;r=g)Brian Sans-Souci (liardom)\n\n![](https:\/\/www.gravatar.com\/avatar\/5a1c57ff7dc66a0d8702f856ceb355fd.jpg?s=32&#038;d=mp&#038;r=g)the sneaky squirrel\n\nMore Details ><\/p>\n<p>#### Unlimited Timeline < 1.6.1 - Missing Authorization\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-27008**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nUnlimited Timeline\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Tran Nguyen Bao Khanh\n\nMore Details ><\/p>\n<p>#### WP Staging Pro <= 6.1.2 - Unauthenticated Information Exposure via getOutdatedPluginsRequest Function\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-3104**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nWP STAGING Pro WordPress Backup Plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/d30e6a858b269fc0c2ddccf3c3327313.jpg?s=32&#038;d=mp&#038;r=g)haidv35\n\nMore Details ><\/p>\n<p>#### wpLike2Get <= 1.2.9 - Unauthenticated Information Exposure\n\n5.3\n\nCVSS Rating  \n**Medium (5.3)**\n\nCVE-ID  \n**CVE-2025-39439**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nwpLike2Get\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/dfc42784669accf02da36cb658a6a355.jpg?s=32&#038;d=mp&#038;r=g)ch4r0n\n\nMore Details ><\/p>\n<p>#### BMA Lite <= 1.4.2 - Authenticated (Administrator+) SQL Injection\n\n4.9\n\nCVSS Rating  \n**Medium (4.9)**\n\nCVE-ID  \n**CVE-2025-39518**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nBMA Lite \u2013 Appointment Booking and Scheduling Plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Pham Van Phuoc\n\nMore Details ><\/p>\n<p>#### Hostel <= 1.1.5.6 - Authenticated (Administrator+) SQL Injection\n\n4.9\n\nCVSS Rating  \n**Medium (4.9)**\n\nCVE-ID  \n**CVE-2025-39566**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nHostel\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)astra.r3verii\n\nMore Details ><\/p>\n<p>#### TS Poll \u2013 Survey, Versus Poll, Image Poll, Video Poll <= 2.4.6 - Authenticated (Administrator+) SQL Injection via 's' Parameter\n\n4.9\n\nCVSS Rating  \n**Medium (4.9)**\n\nCVE-ID  \n**CVE-2025-3470**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nTS Poll \u2013 Survey, Versus Poll, Image Poll, Video Poll\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/4f335379e6c22b34c96df34218ac155f.jpg?s=32&#038;d=mp&#038;r=g)broccoli\n\nMore Details ><\/p>\n<p>#### WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read\n\n4.9\n\nCVSS Rating  \n**Medium (4.9)**\n\nCVE-ID  \n**CVE-2025-3295**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWP Editor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/37cc74b0e1957fee81825154abeae540.jpg?s=32&#038;d=mp&#038;r=g)nquangit\n\nMore Details ><\/p>\n<p>#### Login Manager \u2013 Design Login Page, View Login Activity, Limit Login Attempts <= 2.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via Custom URL\n\n4.4\n\nCVSS Rating  \n**Medium (4.4)**\n\nCVE-ID  \n**CVE-2025-2613**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nLogin Manager \u2013 Design Login Page, View Login Activity, Limit Login Attempts\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/7d4a68019ac73014fd7a41bf4de262d6.jpg?s=32&#038;d=mp&#038;r=g)Arshid KV\n\nMore Details ><\/p>\n<p>#### MaxButtons <= 9.8.3 - Authenticated (Administrator+) Stored Cross-Site Scripting\n\n4.4\n\nCVSS Rating  \n**Medium (4.4)**\n\nCVE-ID  \n**CVE-2025-39444**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWordPress Button Plugin MaxButtons\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/697aca1b58dce62b53c47e23b571f54c.jpg?s=32&#038;d=mp&#038;r=g)ayato\n\nMore Details ><\/p>\n<p>#### Payment Form for PayPal Pro <= 1.1.72 - Authenticated (Administrator+) Stored Cross-Site Scripting\n\n4.4\n\nCVSS Rating  \n**Medium (4.4)**\n\nCVE-ID  \n**CVE-2025-39562**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nPayment Form for PayPal Pro\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Doan Dinh Van\n\nMore Details ><\/p>\n<p>#### WP Post to PDF Enhanced <= 1.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting\n\n4.4\n\nCVSS Rating  \n**Medium (4.4)**\n\nCVE-ID  \n**CVE-2025-39427**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWP Post to PDF Enhanced\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&#038;d=mp&#038;r=g)Nabil Irawan\n\nMore Details ><\/p>\n<p>#### Advanced Dynamic Pricing for WooCommerce <= 4.9.3 - Cross-Site Request Forgery to Settings Update\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39453**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nAdvanced Dynamic Pricing for WooCommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/c36a7211a54c34d3d52be3b1bd8d253e.jpg?s=32&#038;d=mp&#038;r=g)lucky_buddy\n\nMore Details ><\/p>\n<p>#### Advanced Google Maps <= 5.8.4 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39465**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nwp-google-map-gold\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/54d48d97cbd2b84eb914943109eb7d14.jpg?s=32&#038;d=mp&#038;r=g)Nguy\u1ec5n Trung Ki\u00ean\n\nMore Details ><\/p>\n<p>#### Anthologize <= 0.8.3 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39437**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nAnthologize\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&#038;d=mp&#038;r=g)Nabil Irawan\n\nMore Details ><\/p>\n<p>#### Avatar <= 0.1.4 - Authenticated (Subscriber+) Insecure Direct Object Reference\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39434**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nAvatar\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### Barcode Generator for WooCommerce <= 2.0.4 - Authenticated (Subscriber+) Arbitrary Content Deletion\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-32929**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nBarcode Generator for WooCommerce \u2013 Show barcodes on products, orders, invoices and other pages\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/b5bd58d8a8029c69877dc8a75d7889fd.jpg?s=32&#038;d=mp&#038;r=g)K\u00e9vin Mosbahi (Mika)\n\nMore Details ><\/p>\n<p>#### Basic Interactive World Map <= 2.7 - Cross-Site Request Forgery to Settings Update\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39517**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nBasic Interactive World Map\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### bbPress2 shortcode whitelist <= 2.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39432**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nbbPress2 shortcode whitelist\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### BERTHA AI <= 1.12.10.2 - Authenticated (Subscriber+) Arbitrary Content Deletion\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39583**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nBERTHA AI. Your AI co-pilot for WordPress and Chrome\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/01dce303f1fab51371215f21992679d9.jpg?s=32&#038;d=mp&#038;r=g)theviper17y\n\nMore Details ><\/p>\n<p>#### Bknewsticker <= 1.0.5 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39433**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nBknewsticker\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### Bring Fraktguiden for WooCommerce <= 1.11.4 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39559**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nBring Fraktguiden for WooCommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### Bulk Term Editor <= 1.1.4 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39512**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nBulk Term Editor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Skalucy\n\nMore Details ><\/p>\n<p>#### Conditional Payments for WooCommerce <= 3.3.0 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39563**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nConditional Payments for WooCommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/c36a7211a54c34d3d52be3b1bd8d253e.jpg?s=32&#038;d=mp&#038;r=g)lucky_buddy\n\nMore Details ><\/p>\n<p>#### Conditional Shipping for WooCommerce <= 3.4.0 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39564**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nConditional Shipping for WooCommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/c36a7211a54c34d3d52be3b1bd8d253e.jpg?s=32&#038;d=mp&#038;r=g)lucky_buddy\n\nMore Details ><\/p>\n<p>#### Dynamic Post <= 4.10 - Missing Authorization to Authenticated (Subscriber+) Settings Update\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39522**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nDynamic Post\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### ElementsReady Addons for Elementor <= 6.6.2 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39546**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nElementsReady Addons for Elementor\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&#038;d=mp&#038;r=g)Nabil Irawan\n\nMore Details ><\/p>\n<p>#### Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Information Disclosure\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39589**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nEssential Addons for Elementor \u2013 Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits &#038; WooCommerce Builders\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&#038;d=mp&#038;r=g)stealthcopter\n\nMore Details ><\/p>\n<p>#### Ever Accounting <= 2.1.5 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39593**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nEver Accounting \u2013 WordPress Accounting and Invoice Plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Skalucy\n\nMore Details ><\/p>\n<p>#### FS Poster <= 6.5.8 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-30960**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 15, 2025**\n\n**Affected Software**  \nFS Poster - WordPress Social media Auto Poster &#038; Scheduler [Facebook, Instagram, Twitter, Pinterest]\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Rafie Muhammad\n\nMore Details ><\/p>\n<p>#### Grand Restaurant WordPress <= 7.0 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39351**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nGrand Restaurant WordPress\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Ananda Dhakal\n\nMore Details ><\/p>\n<p>#### illow \u2013 Cookies Consent <= 0.2.0 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39426**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nillow \u2013 Cookies Consent\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Skalucy\n\nMore Details ><\/p>\n<p>#### Integration for WooCommerce and QuickBooks <= 1.3.1 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39600**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nIntegration for WooCommerce and QuickBooks\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### IP2Location Variables <= 2.9.5 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39455**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nIP2Location Variables\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/c14731a0f8a0d24cbda30f561fc03441.jpg?s=32&#038;d=mp&#038;r=g)SOPROBRO\n\nMore Details ><\/p>\n<p>#### Live Forms <= 4.8.4 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39560**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nContact Form, Drag and Drop Form Builder Plugin \u2013 Live Forms\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>#### Master Slider <= 3.10.7 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39412**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nMaster Slider \u2013 Responsive Touch Slider\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Ananda Dhakal\n\nMore Details ><\/p>\n<p>#### mLanguage <= 1.6.1 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39430**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nmLanguage\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### My auctions allegro <= 3.6.20 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-27009**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nMy auctions allegro\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&#038;d=mp&#038;r=g)Nabil Irawan\n\nMore Details ><\/p>\n<p>#### Name Directory <= 1.30.0 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39454**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nName Directory\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### Review Wave \u2013 Google Places Reviews <= 1.4.7 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39442**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nReview Wave \u2013 Google Places Reviews\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### Simple Maps <= 0.98 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39424**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nSimple Maps\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### Simple Sitemap \u2013 Create a Responsive HTML Sitemap <= 3.5.14 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39413**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nSimple Sitemap \u2013 Create a Responsive HTML Sitemap\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Ananda Dhakal\n\nMore Details ><\/p>\n<p>#### Sirat <= 1.5.1 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39385**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nSirat\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/258c774aecd81b7d1fa67abf3b576b33.jpg?s=32&#038;d=mp&#038;r=g)Peter Thaleikis\n\nMore Details ><\/p>\n<p>#### Style Manager <= 2.2.7 - Cross-Site Request Forgery to Settings Update\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39425**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nStyle Manager \u2013 Auto-magical system to style your entire WordPress site\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&#038;d=mp&#038;r=g)Nabil Irawan\n\nMore Details ><\/p>\n<p>#### Theme Changer <= 1.3 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39438**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nTheme Changer\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/dfc42784669accf02da36cb658a6a355.jpg?s=32&#038;d=mp&#038;r=g)ch4r0n\n\nMore Details ><\/p>\n<p>#### User Registration &#038; Membership PRO \u2013 Custom Registration Form, Login Form, and User Profile <= 5.1.3 - Cross-Site Request Forgery to User Deletion\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-3284**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 18, 2025**\n\n**Affected Software**  \nUser Registration PRO \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/14c9ac0f163cbf6d8b0f77fce5836577.jpg?s=32&#038;d=mp&#038;r=g)wesley (wcraft)\n\nMore Details ><\/p>\n<p>#### Verge3D <= 4.9.0 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39443**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nVerge3D Publishing and E-Commerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&#038;d=mp&#038;r=g)Nabil Irawan\n\nMore Details ><\/p>\n<p>#### Vitepos <= 3.1.7 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39535**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nVitepos \u2013 Point of sale (POS) plugin for WooCommerce\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)astra.r3verii\n\nMore Details ><\/p>\n<p>#### WooCommerce Products without featured images <= 0.1 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-32545**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 14, 2025**\n\n**Affected Software**  \nWooCommerce Products without featured images\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&#038;d=mp&#038;r=g)0xd4rk5id3\n\nMore Details ><\/p>\n<p>#### WooCommerce Social Login <= 2.8.2 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39472**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWooCommerce - Social Login\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)Ananda Dhakal\n\nMore Details ><\/p>\n<p>#### WordPress REST API Authentication <= 3.6.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39545**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWordPress REST API Authentication\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)chuck\n\nMore Details ><\/p>\n<p>#### WowStore <= 4.2.4 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39571**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWooCommerce Builder &#038; Gutenberg WooCommerce Blocks \u2013 WowStore\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/00000000000000000000000000000000.jpg?s=32&#038;d=mp&#038;r=g)astra.r3verii\n\nMore Details ><\/p>\n<p>#### WP Logger <= 2.2 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39456**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWP Logger\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/b5bd58d8a8029c69877dc8a75d7889fd.jpg?s=32&#038;d=mp&#038;r=g)K\u00e9vin Mosbahi (Mika)\n\nMore Details ><\/p>\n<p>#### WP Simple Booking Calendar <= 2.0.13 - Missing Authorization\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39541**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nWP Simple Booking Calendar\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/15c7bc3e71963fdd7c656346bcf8b159.jpg?s=32&#038;d=mp&#038;r=g)Tr\u01b0\u01a1ng H\u1eefu Ph\u00fac (truonghuuphuc)\n\nMore Details ><\/p>\n<p>#### WP Social Bookmarking <= 3.6 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39422**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWP Social Bookmarking\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### WP Sticky Side Buttons <= 2.1 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39421**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWP Sticky Side Buttons\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### WP Twitter Button <= 1.4.1 - Cross-Site Request Forgery\n\n4.3\n\nCVSS Rating  \n**Medium (4.3)**\n\nCVE-ID  \n**CVE-2025-39420**\n\nPatch Status  \n**Unpatched**\n\nPublished  \n**Apr 17, 2025**\n\n**Affected Software**  \nWP Twitter Button\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/343456e443c863409724aa97bcfa6e3e.jpg?s=32&#038;d=mp&#038;r=g)johska\n\nMore Details ><\/p>\n<p>#### Administrator Z <= 2025.03.28 - Authenticated (Admin+) Directory Traversal\n\n2.7\n\nCVSS Rating  \n**Low (2.7)**\n\nCVE-ID  \n**CVE-2025-39598**\n\nPatch Status  \n**Patched**\n\nPublished  \n**Apr 16, 2025**\n\n**Affected Software**  \nAdministrator Z\n\n**Researcher**  \n\n\n![](https:\/\/www.gravatar.com\/avatar\/e37bf2a629b6924efb95f289b0a7f7e4.jpg?s=32&#038;d=mp&#038;r=g)Nguyen Xuan Chien\n\nMore Details ><\/p>\n<p>* * *<\/p>\n<p>_As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence._<\/p>\n<p>This database is continuously updated, maintained, and populated by Wordfence\u2019s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.<\/p>\n<p>Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.<\/p>\n<p>The post Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025) appeared first on Wordfence.\n        <\/p><\/div>\n<\/p><\/div>\n<div class=\"impact-section\">\n<h3>Impact Assessment<\/h3>\n<table class=\"impact-table\">\n<tr>\n<th>Base Score<\/th>\n<td>10.0<\/td>\n<\/tr>\n<tr>\n<th>Severity<\/th>\n<td style=\"color: #cc0000;\">CRITICAL<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"source-link\">\n<p><a href=\"https:\/\/www.wordfence.com\/blog\/2025\/04\/wordfence-intelligence-weekly-wordpress-vulnerability-report-april-14-2025-to-april-20-2025\/\" target=\"_blank\">View full CVE details<\/a><\/p>\n<\/p><\/div>\n<\/div>\n<style>\n.vulnerability-details {\n    font-family: Arial, sans-serif;\n    max-width: 1200px;\n    margin: 0 auto;\n    padding: 20px;\n}<\/p>\n<p>.info-section, .cvss-section, .cve-section, .description-section, .impact-section {\n    margin-bottom: 30px;\n    background: #f8f9fa;\n    padding: 20px;\n    border-radius: 8px;\n    box-shadow: 0 2px 4px rgba(0,0,0,0.1);\n}<\/p>\n<p>h2 {\n    color: #2c3e50;\n    border-bottom: 2px solid #3498db;\n    padding-bottom: 10px;\n    margin-bottom: 20px;\n}<\/p>\n<p>h3 {\n    color: #34495e;\n    margin-bottom: 15px;\n}<\/p>\n<p>.info-table, .cvss-table, .cve-table, .impact-table {\n    width: 100%;\n    border-collapse: collapse;\n    margin-bottom: 20px;\n}<\/p>\n<p>.info-table th, .cvss-table th, .cve-table th, .impact-table th {\n    background: #e9ecef;\n    padding: 12px;\n    text-align: left;\n    width: 200px;\n}<\/p>\n<p>.info-table td, .cvss-table td, .cve-table td, .impact-table td {\n    padding: 12px;\n    border-bottom: 1px solid #dee2e6;\n}<\/p>\n<p>.description-content {\n    line-height: 1.6;\n    color: #2c3e50;\n}<\/p>\n<p>.source-link {\n    text-align: center;\n    margin-top: 30px;\n}<\/p>\n<p>.source-link a {\n    display: inline-block;\n    padding: 10px 20px;\n    background: #3498db;\n    color: white;\n    text-decoration: none;\n    border-radius: 5px;\n    transition: background 0.3s;\n}<\/p>\n<p>.source-link a:hover {\n    background: #2980b9;\n}\n<\/style>\n","protected":false},"excerpt":{"rendered":"<p>Vulnerability Details Basic Information Title Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025) Type wordfence Published 2025-04-24T13:46:39 Last Seen 2025-04-24T13:53:27&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[9,6,8,36,12,13,7,11,5,100],"class_list":["post-1409","post","type-post","status-publish","format-standard","hentry","category-category_cve","tag-critical","tag-cve","tag-cvss","tag-cvss-100","tag-exploit","tag-news","tag-security","tag-tapic","tag-vulnerability","tag-wordfence"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025) - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=1409\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025) - zero redgem\" \/>\n<meta property=\"og:description\" content=\"Vulnerability Details Basic Information Title Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025) Type wordfence Published 2025-04-24T13:46:39 Last Seen 2025-04-24T13:53:27...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=1409\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-24T09:32:47+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"24 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=1409#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=1409\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025)\",\"datePublished\":\"2025-04-24T09:32:47+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=1409\"},\"wordCount\":4726,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-10.0\",\"exploit\",\"news\",\"Security\",\"tapic\",\"Vulnerability\",\"wordfence\"],\"articleSection\":[\"category_cve\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=1409#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=1409\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=1409\",\"name\":\"Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025) - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-04-24T09:32:47+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=1409#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=1409\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=1409#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025) - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=1409","og_locale":"en_US","og_type":"article","og_title":"Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025) - zero redgem","og_description":"Vulnerability Details Basic Information Title Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025) Type wordfence Published 2025-04-24T13:46:39 Last Seen 2025-04-24T13:53:27...","og_url":"https:\/\/zero.redgem.net\/?p=1409","og_site_name":"zero redgem","article_published_time":"2025-04-24T09:32:47+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"24 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=1409#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=1409"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025)","datePublished":"2025-04-24T09:32:47+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=1409"},"wordCount":4726,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-10.0","exploit","news","Security","tapic","Vulnerability","wordfence"],"articleSection":["category_cve"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=1409#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=1409","url":"https:\/\/zero.redgem.net\/?p=1409","name":"Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025) - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-04-24T09:32:47+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=1409#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=1409"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=1409#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Wordfence Intelligence Weekly WordPress Vulnerability Report (April 14, 2025 to April 20, 2025)"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/1409","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1409"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/1409\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1409"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1409"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1409"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}