সর্বশেষ ওয়ার্ডপ্রেস প্লাগইন দুর্বলতা

2025 08 18funnel builder by funnelkitcve20257654

Critical FunnelKit Privilege Escalation in WordPress//Published on 2025-08-18//CVE-2025-7654

Urgent guide to CVE-2025-7654 Funnel Builder upgrade, mitigations, and WAF protection

2025 08 18real spaces themecve20256758

Critical Unauthenticated Privilege Escalation in Real Spaces//Published on 2025-08-18//CVE-2025-6758

Real Spaces CVE-2025-6758 unauthenticated privilege escalation: detection, patch, hardening

2025 08 18cloudflare image resizingcve20258723

Unauthenticated RCE in Cloudflare Image Resizing Plugin//Published on 2025-08-18//CVE-2025-8723

Urgent security advisory: Cloudflare Image Resizing RCE CVE-2025-8723 with patch and WAF guidance.

2025 08 18real spacescve20258218

Authenticated Privilege Escalation in Real Spaces Plugin//Published on 2025-08-18//CVE-2025-8218

Urgent Real Spaces CVE-2025-8218 privilege escalation guide for WordPress: detection, mitigations, hardening.

2025 08 18automation by autonamicve20257654

WordPress FunnelKit Automations Privilege Escalation Advisory//Published on 2025-08-18//CVE-2025-7654

Urgent guide to FunnelKit Automations privilege escalation CVE 2025-7654 patch and protection

2025 08 16serverbuddy by pluginbuddy.comcve202549895

WordPress ServerBuddy CSRF to PHP Object Injection//Published on 2025-08-16//CVE-2025-49895

Critical ServerBuddy CSRF to PHP Object Injection vulnerability in WordPress with immediate remediation guide

2025 08 16drag and drop multiple file upload – contact form 7cve20258464

WordPress Directory Traversal via Guest User Cookie//Published on 2025-08-16//CVE-2025-8464

Security advisory: directory traversal in Contact Form 7 drag-and-drop uploads, fix 1.3.9.1

2025 08 16advanced iframecve20258089

Authenticated Stored XSS in WordPress iFrame Plugin//Published on 2025-08-16//CVE-2025-8089

Explains CVE-2025-8089 stored XSS in Advanced iFrame, impact, detection, mitigations, and WP-Firewall protection