漏洞列表 353571
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-13035
Code Snippets <= 3.9.1 - Authenticated (Contributor+) PHP Code Injection via extract() and PHP Filter Chains
HIGH 8.0 2025-11-19
codesnippetspro Code Snippets
CVE NVD
CVE-2025-13206
GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'
HIGH 7.2 2025-11-19
stellarwp GiveWP – Donation Plugin and Fundraising Platform givewp givewp
CVE NVD
CVE-2025-12484
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers <= 1.12.19 - Unauthenticated Stored Cross-Site Scripting
HIGH 7.2 2025-11-19
smub Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
CVE NVD
CVE-2025-11243
Allocation of Resources Without Limits or Throttling in Shelly Pro 4PM
HIGH 8.3 2025-11-19
Shelly Pro 4PM
CVE NVD
CVE-2025-12056
Out-of-bounds Read in Shelly Pro 3EM
HIGH 8.3 2025-11-19
Shelly Pro 3EM
CVE NVD
CVE-2025-12535
SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution
MEDIUM 5.3 2025-11-19
brainstormforce SureForms – Contact Form, Custom Form Builder, Calculator & More
CVE NVD
CVE-2025-13085
SiteSEO – SEO Simplified <= 1.3.2 - Insecure Direct Object Reference to Sensitive Post Meta Disclosure
MEDIUM 4.3 2025-11-19
softaculous SiteSEO – SEO Simplified
CVE NVD
CVE-2025-12057
WavePlayer < 3.8.0 - Unauthenticated Arbitrary File Upload
CRITICAL 9.8 2025-11-19
Unknown WavePlayer
CVE NVD
CVE-2025-12814
SiteSEO – SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings Reset
MEDIUM 5.3 2025-11-19
softaculous SiteSEO – SEO Simplified
CVE NVD
CVE-2025-12822
WP Login and Register using JWT <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) API Key Exposure
MEDIUM 4.3 2025-11-19
cyberlord92 WP Login and Register using JWT
CVE NVD
CVE-2025-12359
Responsive Lightbox & Gallery <= 2.5.3 - Authenticated (Author+) Server-Side Request Forgery
MEDIUM 5.4 2025-11-19
dfactory Responsive Lightbox & Gallery
CVE NVD
CVE-2025-12174
Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing Authorization to Authenticated (Subscriber+) Data Export and Slug Update
MEDIUM 6.5 2025-11-19
wpwax Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings
CVE NVD
CVE-2025-12878
FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.13.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wfop_phone Shortcode
MEDIUM 6.4 2025-11-19
amans2k FunnelKit – Funnel Builder for WooCommerce Checkout
CVE NVD
CVE-2025-13145
WP Import – Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV Import
HIGH 7.2 2025-11-19
smackcoders WP Import – Ultimate CSV XML Importer for WordPress
CVE NVD
CVE-2025-12646
Community Events <= 1.5.4 - Unauthenticated SQL Injection
HIGH 7.5 2025-11-19
jackdewey Community Events
CVE NVD
CVE-2025-13054
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MEDIUM 6.4 2025-11-19
cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
CVE NVD
CVE-2025-12710
Pet-Manager – Petfinder <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via kwm-petfinder Shortcode
MEDIUM 6.4 2025-11-19
kwmanagement Pet-Manager – Petfinder
CVE NVD
CVE-2025-12751
WSChat – WordPress Live Chat <= 3.1.6 - Missing Authorization to Authenticated (Subscriber+) Settings Reset
MEDIUM 4.3 2025-11-19
elextensions WSChat – WordPress Live Chat
CVE NVD
CVE-2025-12842
Booking Plugin for WordPress Appointments – Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email Sending
MEDIUM 5.3 2025-11-19
timeslotplugins Booking Plugin for WordPress Appointments – Time Slot
CVE NVD
CVE-2025-12426
Quiz Maker <= 6.7.0.80 - Unauthenticated Sensitive Information Exposure
MEDIUM 5.3 2025-11-19
ays-pro Quiz Maker ays-pro quiz_maker
CVE NVD