সর্বশেষ ওয়ার্ডপ্রেস প্লাগইন দুর্বলতা

2025 10 15oceanpayment creditcard gatewaycve202511728

Oceanpayment Plugin Enables Unauthenticated Order Updates//Published on 2025-10-15//CVE-2025-11728

Unauthenticated order status vulnerability in Oceanpayment Gateway version 6.0 or lower; CVE-2025-11728 mitigation guide

2025 10 15lisfinity corecve20256042

Unauthenticated Privilege Escalation in Lisfinity Core//Published on 2025-10-15//CVE-2025-6042

Explains CVE-2025-6042 unauthenticated privilege escalation in Lisfinity Core and how WP Firewall protects sites

2025 10 15dynamically display postscve202511501

Unauthenticated SQL Injection in Dynamically Display Posts//Published on 2025-10-15//CVE-2025-11501

Urgent security alert for WordPress Dynamically Display Posts vulnerable <=1.1 CVE-2025-11501 with WAF guidance

2025 10 15shortcode buttoncve202510194

Authenticated Stored XSS in Shortcode Button Plugin//Published on 2025-10-15//CVE-2025-10194

WordPress Shortcode Button stored XSS CVE-2025-10194 explained with mitigations and fixes

2025 10 15demo import kitcve202510051

Authenticated File Upload Flaw in Demo Kit//Published on 2025-10-15//CVE-2025-10051

Critical CVE-2025-10051 arbitrary file upload in Demo Import Kit with mitigations.

2025 10 10nex formscve202510185 2

Critical Authenticated SQL Injection in NEX Forms//Published on 2025-10-10//CVE-2025-10185

Essential guide to patching NEX-Forms CVE-2025-10185, detection, mitigation, and WAF hardening

2025 10 10everest backupcve202511380 1

Everest Backup Plugin Authorization Bypass Exposes Data//Published on 2025-10-10//CVE-2025-11380

Protect WordPress sites from Everest Backup CVE-2025-11380 unauthenticated exposure with patch and WAF

2025 10 10ovatheme events managercve20256553

Unauthenticated File Upload in Ovatheme Events Manager//Published on 2025-10-10//CVE-2025-6553

Urgent WordPress vulnerability advisory for Ovatheme Events Manager CVE-2025-6553 unauthenticated file upload patch 1.8.6

2025 10 10nex formscve202510185 1

Authenticated Admin SQL Injection in NEX Forms//Published on 2025-10-10//CVE-2025-10185

Urgent guide to NEX-Forms CVE-2025-10185: mitigation steps and WP-Firewall protection

2025 10 10trinity audiocve20259196

Urgent Trinity Audio Unauthenticated Information Exposure//Published on 2025-10-10//CVE-2025-9196

Trinity Audio CVE-2025-9196 unauthenticated data exposure guide for WordPress risk and mitigations