A vulnerability classified as critical was found in Simple Payment Plugin up to 2.3.8 on WordPress. This vulnerability affects the function create_user. The manipulation leads to improper authentication.
This vulnerability was named CVE-2025-6688. The attack can be initiated remotely. There is no exploit available.
A vulnerability has been found in VR Calendar Plugin up to 2.4.7 on WordPress and classified as problematic. Affected by this vulnerability is the function syncCalendar of the component Calendar Syncinfo. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-5936. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in AB Testing Plugin up to 1.18.2 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation of the argument ID leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-4587. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Pack Elementor Addon Plugin up to 2.1.3 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument slider_options leads to cross site scripting.
This vulnerability was named CVE-2025-6550. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Osom Blocks Plugin up to 1.2.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument class_name leads to cross site scripting.
The identification of this vulnerability is CVE-2025-5940. The attack may be initiated remotely. There is no exploit available.
A vulnerability has been found in BuddyPress Docs Plugin up to 2.2.4 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Download File Handler. The manipulation leads to authorization bypass.
This vulnerability was named CVE-2025-5526. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in Firelight Lightbox Plugin up to 2.3.15 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-5035. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Responsive Lightbox & Gallery Plugin up to 2.5.1 on WordPress. Affected by this issue is some unknown functionality of the component Swipebox Library. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-5093. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.