সর্বশেষ ওয়ার্ডপ্রেস প্লাগইন দুর্বলতা

2025 09 08doccurecve20259112

Authenticated Arbitrary File Upload in Doccure//Published on 2025-09-08//CVE-2025-9112

Urgent CVE-2025-9112 in Doccure WordPress theme enables authenticated file uploads; mitigations and WAF protection

2025 09 08gozacve202510134

Urgent Goza Theme Arbitrary File Deletion Advisory//Published on 2025-09-08//CVE-2025-10134

Goza WordPress theme CVE-2025-10134 unauthenticated file deletion vulnerability; patch 3.2.3 and mitigation insights

2025 09 08gozacve20255394

Unauthenticated Arbitrary File Upload in Goza Theme//Published on 2025-09-08//CVE-2025-5394

Goza CVE-2025-5394 unauthenticated file upload risk; patch to 3.2.3 or deploy WP-Firewall.

2025 09 06adforestcve20258359

Critical AdForest Admin Authentication Bypass//Published on 2025-09-06//CVE-2025-8359

Critical AdForest authentication bypass CVE-2025-8359: patch now with WAF, detection, and incident response

2025 09 05rehubcve20257368

Rehub Theme Vulnerability Exposes Password Protected Posts//Published on 2025-09-05//CVE-2025-7368

Rehub CVE-2025-7368 unauthenticated password-protected post disclosure and WP-Firewall protection

2025 09 05html social share buttonscve20259849

Authenticated Stored Cross Site Scripting Vulnerability//Published on 2025-09-05//CVE-2025-9849

Urgent WordPress Html Social Share Buttons stored XSS CVE-2025-9849 patch now

2025 09 06userswpcve202510003

Authenticated Subscriber SQL Injection in WordPress Plugin//Published on 2025-09-06//CVE-2025-10003

Patch UsersWP CVE-2025-10003 now; mitigate with WAF and secure forms.

2025 09 05rehubcve20257366

Unauthenticated Rehub Shortcode Execution Risk//Published on 2025-09-05//CVE-2025-7366

WordPress Rehub CVE-2025-7366 unauthenticated shortcode execution with immediate protection guidance

2025 09 06smart table buildercve20259126

Authenticated Stored XSS in Smart Table Builder//Published on 2025-09-06//CVE-2025-9126

WordPress security alert: stored XSS in Smart Table Builder up to 1.0.1 and remediation

2025 09 05new simple gallerycve202558881

Critical SQL Injection in Simple Gallery Plugin//Published on 2025-09-05//CVE-2025-58881

CVE-2025-58881 SQL injection in WordPress New Simple Gallery and practical mitigations