সর্বশেষ ওয়ার্ডপ্রেস প্লাগইন দুর্বলতা

2025 08 16profilepresscve20258878

WordPress ProfilePress Shortcode Vulnerability Enables Unauthenticated Execution//Published on 2025-08-16//CVE-2025-8878

Urgent ProfilePress CVE-2025-8878 unauthenticated shortcode execution; update to 4.16.5.

2025 08 16soledadcve20258105

Critical Soledad WordPress Shortcode Execution Unauthenticated//Published on 2025-08-16//CVE-2025-8105

Soledad theme CVE-2025-8105 unauthenticated shortcode risk, detection, patching and WP-Firewall protection

2025 08 16profile buildercve20258896

Stored XSS in WordPress User Profile Builder//Published on 2025-08-16//CVE-2025-8896

Urgent: Patch Profile Builder CVE-2025-8896 stored XSS to 3.14.4; mitigations and WAF tips.

2025 08 16betterdocscve20257499

WordPress BetterDocs Authorization Gap Exposes Private Posts//Published on 2025-08-16//CVE-2025-7499

Critical BetterDocs private content exposure CVE-2025-7499: patch to 4.1.2 and mitigations.

2025 08 16wpgymcve20253671

WordPress Gym Plugin Local File Inclusion Escalation//Published on 2025-08-16//CVE-2025-3671

Critical WPGYM LFI CVE-2025-3671 exploit guide with urgent mitigations and WAF patches

2025 08 16intl datetime calendarcve20258293

WordPress Authenticated Stored XSS Via Date Parameter//Published on 2025-08-16//CVE-2025-8293

Urgent CVE-2025-8293 stored XSS in Intl DateTime Calendar WordPress plugin and defenses

2025 08 16wpgymcve20256080

WordPress WPGYM Admin Account Creation Bypass//Published on 2025-08-16//CVE-2025-6080

Urgent guide to WPGYM CVE-2025-6080 privilege escalation and WP-Firewall protection

2025 08 16school managementcve202412612

Unauthenticated WordPress School Management Plugin SQL Injection//Published on 2025-08-16//CVE-2024-12612

Urgent guide to mitigating unauthenticated SQL injection in School Management plugin versions <= 93.2.0

2025 08 15add user metacve20257688

WordPress Add User Meta CSRF Stored XSS//Published on 2025-08-15//CVE-2025-7688

Urgent WordPress CVE-2025-7688: CSRF stored XSS in Add User Meta plugin; mitigation guidance.

2025 08 15linux promotional plugincve20257668

WordPress Plugin CSRF to Stored XSS Vulnerability//Published on 2025-08-15//CVE-2025-7668

Technical breakdown, risk assessment, and mitigation steps for CVE-2025-7668 Linux Promotional Plugin.