漏洞列表 353571
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-11764
Shortcodes Bootstrap <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
fastmover Shortcodes Bootstrap
CVE NVD
CVE-2025-10938
UiPress lite <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure
MEDIUM 6.5 2025-11-21
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
CVE NVD
CVE-2025-11771
Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.6 - Missing Authentication to Unauthenticated Presale Update
MEDIUM 5.3 2025-11-21
beycanpress Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO
CVE NVD
CVE-2025-11003
UiPress lite <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
CVE NVD
CVE-2025-11799
Affiliate AI Lite <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
rustaurius Affiliate AI Lite
CVE NVD
CVE-2025-11456
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload
CRITICAL 9.8 2025-11-21
elextensions ELEX WordPress HelpDesk & Customer Ticketing System elula wsdesk
CVE NVD
CVE-2025-12881
Return Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Order Message Read
MEDIUM 5.4 2025-11-21
wpswings Return Refund and Exchange For WooCommerce
CVE NVD
CVE-2025-11815
UiPress lite | Effortless custom dashboards, admin themes and pages <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update
MEDIUM 4.3 2025-11-21
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
CVE NVD
CVE-2025-13159
Flo Forms – Easy Drag & Drop Form Builder <= 1.0.43 - Unauthenticated Stored Cross-Site Scripting via SVG Upload
HIGH 7.1 2025-11-21
flothemesplugins Flo Forms – Easy Drag & Drop Form Builder
CVE NVD
CVE-2025-13134
AuthorSure <= 2.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
MEDIUM 6.1 2025-11-21
powerblogservice AuthorSure
CVE NVD
CVE-2025-12135
WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting
HIGH 7.2 2025-11-21
iqonicdesign WPBookit
CVE NVD
CVE-2025-11885
EchBay Admin Security <= 1.3.0 - Reflected Cross-Site Scripting
MEDIUM 6.1 2025-11-21
itvn9online EchBay Admin Security
CVE NVD
CVE-2025-13142
Custom Post Type <= 1.0 - Cross-Site Request Forgery to Custom Post Type Deletion
MEDIUM 4.3 2025-11-21
farvehandleren Custom Post Type
CVE NVD
CVE-2025-11768
Islamic Phrases <= 2.12.2015 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
darto Islamic Phrases
CVE NVD
CVE-2025-11770
BrightTALK WordPress Shortcode <= 2.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
billybigpotatoes BrightTALK WordPress Shortcode
CVE NVD
CVE-2025-11767
Tips Shortcode <= 0.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
fpcorso Tips Shortcode
CVE NVD
CVE-2025-12894
Import WP – Export and Import CSV and XML files to WordPress <= 2.14.17 - Unauthenticated Information Exposure
MEDIUM 5.3 2025-11-21
jcollings Import WP – Export and Import CSV and XML files to WordPress
CVE NVD
CVE-2025-11801
AudioTube <= 0.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
davidangel AudioTube
CVE NVD
CVE-2025-12138
URL Image Importer <= 1.0.6 - Authenticated (Author+) Arbitrary File Upload
HIGH 8.8 2025-11-21
bww URL Image Importer
CVE NVD
CVE-2025-11765
Stock Tools <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-21
developdaly Stock Tools
CVE NVD