সর্বশেষ ওয়ার্ডপ্রেস প্লাগইন দুর্বলতা

2025 10 18theme editorcve20259890

Theme Editor CSRF Enables Remote Code Execution//Published on 2025-10-18//CVE-2025-9890

CSRF to RCE in Theme Editor <=3.0 explained with remediations and WAF guidance.

2025 10 16felan frameworkcve202510849

Felan Framework Authorization Bypass Enables Plugin Activation//Published on 2025-10-16//CVE-2025-10849

Felan Framework CVE-2025-10849 vulnerability and WP-Firewall mitigation guidance and update to 1.1.5

2025 10 15wp google mapcve202511365

Authenticated SQL Injection in WordPress Google Map//Published on 2025-10-15//CVE-2025-11365

Urgent guide to CVE-2025-11365 WP Google Map SQL injection and mitigation steps

2025 10 16blindmatrix e commercecve202510406

Critical LFI in BlindMatrix Ecommerce Plugin//Published on 2025-10-16//CVE-2025-10406

Urgent guide to BlindMatrix LFI CVE-2025-10406, mitigation, patch, and WAF tips.

2025 10 15quick featured imagescve202511176 2

Critical IDOR in Quick Featured Images Plugin//Published on 2025-10-15//CVE-2025-11176

Explains Quick Featured Images IDOR CVE-2025-11176 mitigations and patch 13.7.3

2025 10 16truelysell corecve202510742

Unauthenticated Password Reset Flaw in Truelysell//Published on 2025-10-16//CVE-2025-10742

Unauthenticated password-change vulnerability CVE-2025-10742 affects Truelysell Core <=1.8.6; remediation and WAF guidance.

2025 10 16felan frameworkcve202510850

Urgent Felan Framework Hardcoded Credentials Vulnerability//Published on 2025-10-16//CVE-2025-10850

Urgent Felan Framework CVE-2025-10850 vulnerability advisory with immediate WordPress patch guidance

2025 10 15pz linkcardcve20258594

Critical SSRF Vulnerability in Pz LinkCard Plugin//Published on 2025-10-15//CVE-2025-8594

SSRF in Pz-LinkCard prior to 2.5.7 (CVE-2025-8594) and WP-Firewall protection

2025 10 15wp bookwidgetscve202510139 1

Critical Authenticated Stored XSS in BookWidgets Plugin//Published on 2025-10-15//CVE-2025-10139

Urgent analysis of WP BookWidgets stored XSS CVE-2025-10139 and mitigations.

2025 10 15wpbakery page buildercve202511160 1

Urgent WPBakery Stored Cross Site Scripting Alert//Published on 2025-10-15//CVE-2025-11160

WPBakery Stored XSS CVE-2025-11160 explained: risk, detection and remediation steps