A vulnerability was found in Gallery Blocks with Lightbox Plugin up to 3.3.0 on WordPress and classified as problematic. This affects the function edit_posts of the component AJAX Handler. Executing manipulation can lead to missing authorization.
This vulnerability is handled as CVE-2025-14288. The attack can be executed remotely. There is not any exploit available.
A vulnerability marked as problematic has been reported in Custom Frames Plugin up to 1.0.1 on WordPress. The impacted element is the function customframe of the component Shortcode Handler. This manipulation of the argument Class causes cross site scripting.
This vulnerability is tracked as CVE-2025-13705. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability has been found in WP3D Model Import Viewer Plugin up to 1.0.7 on WordPress and classified as critical. This issue affects the function handle_import_file. This manipulation causes unrestricted upload.
This vulnerability is handled as CVE-2025-13094. The attack can be initiated remotely. There is not any exploit available.
A vulnerability marked as problematic has been reported in Solutions Ad Manager Plugin up to 1.0.0 on WordPress. This issue affects some unknown processing. The manipulation of the argument sam-redirect-to leads to open redirect.
This vulnerability is listed as CVE-2025-14451. The attack may be initiated remotely. There is no available exploit.
A vulnerability, which was classified as problematic, was found in Doubly Plugin up to 1.0.46 on WordPress. This vulnerability affects unknown code of the component ZIP File Import. The manipulation results in deserialization.
This vulnerability is known as CVE-2025-14476. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in Lucky Draw Contests Plugin up to 4.2 on WordPress. It has been rated as problematic. This affects an unknown function of the file misc-settings.php of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2025-14462. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability classified as critical has been found in Extensive VC Addons for WPBakery Page Builder Plugin up to 1.9.1 on WordPress. This vulnerability affects the function extensive_vc_get_module_template_part. The manipulation of the argument shortcode_name leads to file inclusion.
This vulnerability is documented as CVE-2025-14475. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in AnnunciFunebri Impresa Plugin up to 4.7.0 on WordPress. It has been classified as problematic. This impacts the function annfu_reset_options of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2025-14447. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in Postem Ipsum Plugin up to 3.0.1 on WordPress. It has been rated as critical. Affected by this vulnerability is the function postem_ipsum_generate_users. This manipulation causes missing authorization.
The identification of this vulnerability is CVE-2025-14397. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability described as problematic has been identified in Userback Plugin up to 1.0.15 on WordPress. Impacted is the function userback_get_json. The manipulation results in missing authorization.
This vulnerability is cataloged as CVE-2025-14540. The attack may be launched remotely. There is no exploit available.
A vulnerability labeled as problematic has been found in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of weak hash.
This vulnerability is known as CVE-2025-14636. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability classified as problematic has been found in Call Blocker App 6.6.3 on Android. The affected element is an unknown function of the component Database Handler. Performing manipulation results in denial of service.
This vulnerability was named CVE-2023-29727. The attack needs to be approached locally. There is no available exploit.
A vulnerability identified as problematic has been detected in SoLive up to 1.6.20 on Android. This affects an unknown part of the component SharedPreference File Handler. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2023-29731. An attack has to be approached locally. There is no exploit available.
A vulnerability described as problematic has been identified in Call Blocker App 6.6.3 on Android. Impacted is an unknown function. Such manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2023-29726. Local access is required to approach this attack. No exploit exists.
A vulnerability identified as problematic has been detected in Call Blocker App 6.6.3 on Android. This affects an unknown function. Performing manipulation results in Local Privilege Escalation.
This vulnerability is reported as CVE-2023-29728. The attack requires a local approach. No exploit exists.
A vulnerability labeled as problematic has been found in SoLive up to 1.6.20 on Android. This vulnerability affects unknown code of the component SharedPreference File Handler. The manipulation results in incorrect default permissions.
This vulnerability is known as CVE-2023-29732. Attacking locally is a requirement. No exploit is available.