সর্বশেষ ওয়ার্ডপ্রেস প্লাগইন দুর্বলতা

2025 11 17cookieyescve

Essential Patch Management for WordPress Security//Published on 2025-11-17//N/A

Urgent WordPress vulnerability update: patch plugins/themes, scan malware, enable WAF, follow incident response

2025 11 17creta testimonial showcasecve202510686

Critical Local File Inclusion in Creta Testimonial//Published on 2025-11-17//CVE-2025-10686

Vulnerability CVE-2025-10686: LFI in Creta Testimonial Showcase; WordPress plugin; Editor access risk; update to 1.2.4.

2025 11 17appointment booking calendarcve202564261

Critical Access Control Flaw in Booking Plugin//Published on 2025-11-17//CVE-2025-64261

Urgent guide to CVE-2025-64261 in Appointment Booking Calendar, upgrade to 1.3.96 and apply mitigations.

2025 11 16coschedulecve202549913

CoSchedule Plugin Vulnerable to Access Control Bypass//Published on 2025-11-16//CVE-2025-49913

Urgent WordPress CoSchedule CVE-2025-49913 vulnerability: patch now, mitigations, and monitoring.

2025 11 15envira photo gallerycve202512377

Envira Photo Gallery Authorization Bypass Alert//Published on 2025-11-15//CVE-2025-12377

Envira Photo Gallery CVE-2025-12377 broken access control guide with mitigations and WP-Firewall protection

2025 11 15theater for wordpresscve202564259

Broken Access Control in Theater Plugin//Published on 2025-11-15//CVE-2025-64259

Vendor-focused guide to Theater for WordPress CVE-2025-64259: mitigation and hardening

2025 11 14modula image gallerycve202512494

Authenticated Author Arbitrary Image File Move Vulnerability//Published on 2025-11-14//CVE-2025-12494

CVE-2025-12494 vulnerability in Modula Image Gallery, risks, fixes, and WAF hardening

2025 11 14contest gallerycve202512849

WordPress Contest Gallery Authorization Vulnerability Alert//Published on 2025-11-14//CVE-2025-12849

Urgent guide to Contest Gallery vulnerability CVE-2025-12849 unauthenticated access and patch update to 28.0.3

2025 11 14all in one seo packcve202512847

Missing Authorization Enables Contributor Media Deletion//Published on 2025-11-14//CVE-2025-12847

CVE-2025-12847 vulnerability in All In One SEO Pack enabling media deletion; detection and mitigations.