NuytsTech Security

CVE-2025-30594

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in NotFound Include URL allows Path Traversal. This issue affects Include URL: from n/a through 0.3.5. Assigner : audit@patchstack.com More information :...

CVE-2025-30589

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in NotFound Flickr set slideshows allows SQL Injection. This issue affects Flickr set slideshows: from n/a through 0.9. Assigner : audit@patchstack.com...

CVE-2025-30579

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Jakeii Pesapal Gateway for Woocommerce allows Reflected XSS. This issue affects Pesapal Gateway for Woocommerce: from n/a through 2.1.0. Assigner : audit@patchstack.com...

CVE-2025-30559

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in NotFound Kento WordPress Stats allows Stored XSS. This issue affects Kento WordPress Stats: from n/a through 1.1. Assigner : audit@patchstack.com More information...

CVE-2025-30548

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in VarDump s.r.l. Advanced Post Search allows Reflected XSS. This issue affects Advanced Post Search: from n/a through 1.1.0. Assigner : audit@patchstack.com More...

CVE-2025-30547

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in David Tufts WP Cards allows Reflected XSS. This issue affects WP Cards: from n/a through 1.5.1. Assigner : audit@patchstack.com More information :...

CVE-2025-30544

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in NotFound OK Poster Group allows Reflected XSS. This issue affects OK Poster Group: from n/a through 1.1. Assigner : audit@patchstack.com More information...

CVE-2025-30520

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in crosstec Breezing Forms allows Reflected XSS. This issue affects Breezing Forms: from n/a through 1.2.8.11. Assigner : audit@patchstack.com More information : https://patchstack.com/database/wordpress/plugin/breezing-forms/vulnerability/wordpress-breezing-forms-plugin-1-2-8-11-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve

CVE-2025-2048

The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files...

CVE-2025-1665

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin’s shortcodes in all versions up to, and including, 3.11.14 due to insufficient input sanitization and output...

CVE-2025-2008

The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import_single_post_as_csv() function in all versions up to, and...