漏洞列表 353262
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-13141
HT Mega – Absolute Addons For Elementor <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection
MEDIUM 6.4 2025-11-21
devitemsllc HT Mega – Absolute Addons For Elementor
CVE NVD
CVE-2025-13149
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories <= 4.9.1 - Authenticated (Author+) Missing Authorization to Post/Page Status Modification
MEDIUM 4.3 2025-11-21
publishpress Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
CVE NVD
CVE-2025-11826
WP Company Info <= 1.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MEDIUM 6.4 2025-11-21
bdeleasa WP Company Info
CVE NVD
CVE-2025-11973
简数采集器 <= 2.6.3 - Authenticated (Admin+) Arbitrary File Read
MEDIUM 4.9 2025-11-21
zhengdon 简数采集器
CVE NVD
CVE-2025-12039
BigBuy Dropshipping Connector for WooCommerce <= 2.0.5 - Unauthenticated IP Spoofing to phpinfo() Exposure
MEDIUM 5.3 2025-11-21
devsmip BigBuy Dropshipping Connector for WooCommerce
CVE NVD
CVE-2025-11803
WPSite Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
wpfanyi WPSite Shortcode
CVE NVD
CVE-2025-11800
Surbma | MiniCRM Shortcode <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
surbma Surbma | MiniCRM Shortcode
CVE NVD
CVE-2025-11985
Realty Portal <= 0.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
HIGH 8.8 2025-11-21
nootheme Realty Portal
CVE NVD
CVE-2025-11802
Bulma Shortcodes <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
bartboy011 Bulma Shortcodes
CVE NVD
CVE-2025-11773
Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.6 - Missing Authorization to Authenticated (Subscriber+) Contract Address Update
MEDIUM 4.3 2025-11-21
beycanpress Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO
CVE NVD
CVE-2025-11763
Display Pages Shortcode <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
rustybadrobot Display Pages Shortcode
CVE NVD
CVE-2025-13135
HotelRunner Booking Widget <= 5.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
integrationshotelrunner HotelRunner Booking Widget
CVE NVD
CVE-2025-11764
Shortcodes Bootstrap <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
fastmover Shortcodes Bootstrap
CVE NVD
CVE-2025-10938
UiPress lite <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure
MEDIUM 6.5 2025-11-21
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
CVE NVD
CVE-2025-11771
Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.6 - Missing Authentication to Unauthenticated Presale Update
MEDIUM 5.3 2025-11-21
beycanpress Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO
CVE NVD
CVE-2025-11003
UiPress lite <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
CVE NVD
CVE-2025-11799
Affiliate AI Lite <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
rustaurius Affiliate AI Lite
CVE NVD
CVE-2025-11456
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload
CRITICAL 9.8 2025-11-21
elextensions ELEX WordPress HelpDesk & Customer Ticketing System elula wsdesk
CVE NVD
CVE-2025-12881
Return Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Order Message Read
MEDIUM 5.4 2025-11-21
wpswings Return Refund and Exchange For WooCommerce
CVE NVD
CVE-2025-11815
UiPress lite | Effortless custom dashboards, admin themes and pages <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update
MEDIUM 4.3 2025-11-21
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
CVE NVD