NuytsTech Security

CVE-2025-48319

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in gslauraspeck Mesa Mesa Reservation Widget allows Stored XSS. This issue affects Mesa Mesa Reservation Widget: from n/a through 1.0.0. More information :...

CVE-2025-48316

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in ItayXD Responsive Mobile-Friendly Tooltip allows Stored XSS. This issue affects Responsive Mobile-Friendly Tooltip: from n/a through 1.6.6. More information : https://patchstack.com/database/wordpress/plugin/responsive-mobile-friendly-tooltip/vulnerability/wordpress-responsive-mobile-friendly-tooltip-plugin-1-6-6-cross-site-scripting-xss-vulnerability?_s_id=cve

CVE-2025-48314

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in salubrio Add Code To Head allows Stored XSS. This issue affects Add Code To Head: from n/a through 1.17. More information :...

CVE-2025-48308

Cross-Site Request Forgery (CSRF) vulnerability in nonletter Newsletter subscription optin module allows Stored XSS. This issue affects Newsletter subscription optin module: from n/a through 1.2.9. More information : https://patchstack.com/database/wordpress/plugin/newsletter-subscription-widget-for-sendblaster/vulnerability/wordpress-newsletter-subscription-optin-module-plugin-1-2-9-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve