প্লাগইন দুর্বলতা

2025 11 16coschedulecve202549913

CoSchedule Plugin Vulnerable to Access Control Bypass//Published on 2025-11-16//CVE-2025-49913

Urgent WordPress CoSchedule CVE-2025-49913 vulnerability: patch now, mitigations, and monitoring.

2025 11 15envira photo gallerycve202512377

Envira Photo Gallery Authorization Bypass Alert//Published on 2025-11-15//CVE-2025-12377

Envira Photo Gallery CVE-2025-12377 broken access control guide with mitigations and WP-Firewall protection

2025 11 15theater for wordpresscve202564259

Broken Access Control in Theater Plugin//Published on 2025-11-15//CVE-2025-64259

Vendor-focused guide to Theater for WordPress CVE-2025-64259: mitigation and hardening

2025 11 14modula image gallerycve202512494

Authenticated Author Arbitrary Image File Move Vulnerability//Published on 2025-11-14//CVE-2025-12494

CVE-2025-12494 vulnerability in Modula Image Gallery, risks, fixes, and WAF hardening

2025 11 14contest gallerycve202512849

WordPress Contest Gallery Authorization Vulnerability Alert//Published on 2025-11-14//CVE-2025-12849

Urgent guide to Contest Gallery vulnerability CVE-2025-12849 unauthenticated access and patch update to 28.0.3

2025 11 14all in one seo packcve202512847

Missing Authorization Enables Contributor Media Deletion//Published on 2025-11-14//CVE-2025-12847

CVE-2025-12847 vulnerability in All In One SEO Pack enabling media deletion; detection and mitigations.

2025 11 12wishlist and save for later for woocommercecve202512087

Subscriber IDOR Permits Wishlist Item Deletion//Published on 2025-11-12//CVE-2025-12087

Urgent IDOR in Wishlist and Save for later for WooCommerce; update to 1.1.23.

2025 11 10add multiple markercve202511999

Unauthorized Settings Update in Add Multiple Marker//Published on 2025-11-10//CVE-2025-11999

Urgent: WordPress unauthenticated settings update flaw in Add Multiple Marker plugin (CVE-2025-11999)

2025 11 10document pro elementorcve202511997

Document Pro Elementor Unauthenticated Information Exposure//Published on 2025-11-10//CVE-2025-11997

Urgent guide to mitigating unauthenticated data exposure in Document Pro Elementor CVE-2025-11997 with WAF