সর্বশেষ ওয়ার্ডপ্রেস প্লাগইন দুর্বলতা

2025 10 15yourmembership single sign oncve202510648

YourMembership SSO Unauthenticated Access Exposes Data//Published on 2025-10-15//CVE-2025-10648

Critical advisory on YM SSO Login CVE-2025-10648 unauthenticated data exposure and mitigations

2025 10 15quick social logincve202510140

Authenticated Stored XSS in Quick Social Login//Published on 2025-10-15//CVE-2025-10140

Urgent guide to mitigating stored XSS CVE-2025-10140 in Quick Social Login for WordPress

2025 10 15digisellercve202510141

Authenticated Contributor Stored XSS in Digiseller//Published on 2025-10-15//CVE-2025-10141

Urgent WordPress vulnerability: Digiseller <=1.3.0 stored XSS CVE-2025-10141 with mitigations

2025 10 15topbarcve202510300

TopBar Plugin CSRF Enables Unauthorized Settings Changes//Published on 2025-10-15//CVE-2025-10300

Urgent CSRF vulnerability in TopBar <=1.0.0 CVE-2025-10300 with immediate mitigations and virtual patching

2025 10 15zip attachmentscve202511692

Authorization Bypass in Zip Attachments Plugin//Published on 2025-10-15//CVE-2025-11692

CVE-2025-11692 Zip Attachments vulnerability analysis with mitigation and WP-Firewall protection

2025 10 15ownid passwordless logincve202510294

Critical OwnID Passwordless Login Authentication Bypass//Published on 2025-10-15//CVE-2025-10294

Urgent step by step mitigation for OwnID Passwordless Login CVE-2025-10294 WordPress

2025 10 15onoffice for wp websitescve202510045

Critical Authenticated Editor SQL Injection in onOffice//Published on 2025-10-15//CVE-2025-10045

Authenticated SQL injection risk in onOffice for WP‑Websites <=5.7 with WAF mitigation guidance.

2025 10 15ova adventcve20258561

Authenticated Stored XSS in Ova Advent Plugin//Published on 2025-10-15//CVE-2025-8561

Ova Advent CVE-2025-8561 stored XSS guide: detection, remediation, and WAF protection.

2025 10 15theme importercve202510312

Critical Theme Importer Cross Site Request Forgery//Published on 2025-10-15//CVE-2025-10312

CVE-2025-10312 CSRF in Theme Importer <=1.0 and actionable WordPress protection guidance.

2025 10 15zip attachmentscve202511701

Missing Authorization Exposes Protected Post Attachments//Published on 2025-10-15//CVE-2025-11701

Zip Attachments vulnerability exposes private attachments; fixes, mitigations, and virtual patch guidance