Category: Vulnerabilities

CVE-2025-1665

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin’s shortcodes in all versions up to, and including, 3.11.14 due to insufficient input sanitization and output...

CVE-2025-31024

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in randyjensen RJ Quickcharts allows SQL Injection. This issue affects RJ Quickcharts: from n/a through 0.6.1. Assigner : audit@patchstack.com More information...

CVE-2025-30774

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Ays Pro Quiz Maker allows SQL Injection. This issue affects Quiz Maker: from n/a through 6.6.8.7. Assigner : audit@patchstack.com More...

CVE-2025-30870

Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from...

CVE-2025-2048

The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files...

CVE-2025-30782

Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) vulnerability in WP Shuffle Subscribe to Download Lite allows PHP Local File Inclusion. This issue affects Subscribe to Download Lite:...

CVE-2025-30876

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Ads by WPQuads Ads by WPQuads allows SQL Injection. This issue affects Ads by WPQuads: from n/a through 2.0.87.1. Assigner...

CVE-2025-30793

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in Property Hive Houzez Property Feed allows Path Traversal. This issue affects Houzez Property Feed: from n/a through 2.5.4. Assigner : audit@patchstack.com...