1361
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Abinav Thakuri WordPress Signature allows Cross Site Request Forgery. This issue affects WordPress Signature: from n/a through 0.1.
|
CWE-352
Origin Validation Error
|
CVE-2025-22704
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1362
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder allows Stored XSS. This issue affects Forge – Front-End Page Builder: from n/a through 1.4.6.
|
CWE-352
Origin Validation Error
|
CVE-2025-22703
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1363
|
- |
|
-
|
-
|
Server-Side Request Forgery (SSRF) vulnerability in NotFound Traveler Layout Essential For Elementor. This issue affects Traveler Layout Essential For Elementor: from n/a through 1.0.8.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-22701
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1364
|
- |
|
-
|
-
|
Authorization Bypass Through User-Controlled Key vulnerability in NirWp Team Nirweb support. This issue affects Nirweb support: from n/a through 3.0.3.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-22695
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1365
|
- |
|
-
|
-
|
Missing Authorization vulnerability in theDotstore Hide Shipping Method For WooCommerce. This issue affects Hide Shipping Method For WooCommerce: from n/a through 1.5.0.
|
CWE-862
Missing Authorization
|
CVE-2025-22694
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1366
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery Contest Gallery allows SQL Injection. This issue affects Contest Gallery: from n/…
|
CWE-89
SQL Injection
|
CVE-2025-22693
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1367
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel allows SQL Injection. This issue affects WP Travel: from n/a through 10.1.0.
|
CWE-89
SQL Injection
|
CVE-2025-22691
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1368
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in DigiTimber DigiTimber cPanel Integration allows Stored XSS. This issue affects DigiTimber cPanel Integration: from n/a through 1.4.6.
|
CWE-352
Origin Validation Error
|
CVE-2025-22690
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1369
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Ederson Peka Unlimited Page Sidebars allows Stored XSS. This issue affects Unlimited Page Sidebars: from n/a through 0.2.6.
|
CWE-352
Origin Validation Error
|
CVE-2025-22688
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1370
|
- |
|
-
|
-
|
Missing Authorization vulnerability in GSheetConnector CF7 Google Sheets Connector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 Google Sheets Connec…
|
CWE-862
Missing Authorization
|
CVE-2025-22686
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|