Total
9949 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-15507 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_sync_usage() function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to modify the plugin's license status and credit balance. | |||||
| CVE-2025-15476 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bucketlister_do_admin_ajax() function in all versions up to, and including, 0.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add delete or modify arbitrary bucket list items. | |||||
| CVE-2025-15475 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to change the status of pending WooCommerce orders to paid/completed/on hold. | |||||
| CVE-2025-15473 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type. | |||||
| CVE-2025-15466 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple AJAX actions in all versions up to, and including, 3.6.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to view, create, modify, clone, delete, and reassign ownership of galleries created by other users, including administrators. | |||||
| CVE-2025-15445 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged-in user, like subscriber, to perform privileged operations. An attacker can install and activate a from a user-supplied URL, leading to arbitrary PHP code execution, and also import demo content that rewrites site configuration, including Restaurant Cafeteria WordPress theme through 0.4.6_mods, pages, menus, and front page settings. | |||||
| CVE-2025-15406 | 1 Phpgurukul | 1 Online Course Registration | 2026-06-17 | 6.5 MEDIUM | 6.3 MEDIUM |
| A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |||||
| CVE-2025-15405 | 1 Phpems | 1 Phpems | 2026-06-17 | 5.0 MEDIUM | 4.3 MEDIUM |
| A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. | |||||
| CVE-2025-15400 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality. | |||||
| CVE-2025-15390 | 1 Phpgurukul | 1 Small Crm | 2026-06-17 | 6.5 MEDIUM | 6.3 MEDIUM |
| A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. | |||||
| CVE-2025-15347 | 2026-06-17 | N/A | 8.8 HIGH | ||
| The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the get_items_permissions_check function in all versions up to, and including, 1.1.12. This makes it possible for authenticated attackers, with contributor level access and above, to update arbitrary WordPress options. | |||||
| CVE-2025-15330 | 1 Tanium | 1 Deploy | 2026-06-17 | N/A | 8.8 HIGH |
| Tanium addressed an improper input validation vulnerability in Deploy. | |||||
| CVE-2025-15327 | 1 Tanium | 1 Deploy | 2026-06-17 | N/A | 4.3 MEDIUM |
| Tanium addressed an improper access controls vulnerability in Deploy. | |||||
| CVE-2025-15326 | 1 Tanium | 1 Patch | 2026-06-17 | N/A | 4.3 MEDIUM |
| Tanium addressed an improper access controls vulnerability in Patch. | |||||
| CVE-2025-15289 | 1 Tanium | 1 Interact | 2026-06-17 | N/A | 3.1 LOW |
| Tanium addressed an improper access controls vulnerability in Interact. | |||||
| CVE-2025-15285 | 2026-06-17 | N/A | 7.5 HIGH | ||
| The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the checkBlogAuthentication() and checkCategoryAuthentication() functions in all versions up to, and including, 2.2.1. These authorization functions only implement basic API key authentication but fail to implement WordPress capability checks. This makes it possible for unauthenticated attackers to create, modify, and delete blog posts and categories. | |||||
| CVE-2025-15260 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'ajax' function. This makes it possible for authenticated attackers, with subscriber level access and above, to modify, add, or delete loyalty program earning rules, including manipulating point multipliers to arbitrary values. | |||||
| CVE-2025-15235 | 1 Quantatw | 1 Qoca Aim | 2026-06-17 | N/A | 6.5 MEDIUM |
| QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing authenticated remote attackers to modify specific network packet parameters, enabling certain system functions to access other users' files. | |||||
| CVE-2025-15157 | 2026-06-17 | N/A | 8.8 HIGH | ||
| The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'srm_restore_options_defaults' function in all versions up to, and including, 3.1.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. | |||||
| CVE-2025-15070 | 1 Gmission | 1 Web Fax | 2026-06-17 | N/A | 5.5 MEDIUM |
| Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse. This issue affects Web Fax: from 3.0 before 3.0.1 | |||||
