NuytsTech Security

CVE-2025-13885

The Zenost Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ and ‘target’ parameters in the `button` shortcode in all versions up to, and including, 1.0 due to insufficient input...

CVE-2025-13884

The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_css’ parameter in the `bg-hide-email-address` shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization...

CVE-2025-13866

The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the flow_flow_social_auth AJAX action in versions 3.0.0 to 4.7.5. This makes it...

CVE-2025-13850

The LS Google Map Router plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘map_type’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping....

CVE-2025-13846

The Easy Map Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This...

CVE-2025-13843

The VigLink SpotLight By ShortCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘float’ parameter of the ‘spotlight’ shortcode in all versions up to, and including, 1.0.a due to insufficient input...

CVE-2025-13840

The BUKAZU Search widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode’ parameter of the ‘bukazu_search’ shortcode in all versions up to, and including, 3.3.2 due to insufficient input sanitization...

CVE-2025-13747

The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode function in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping...

CVE-2025-13440

The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.10. This is due to a missing capability check on the deleteWishlist() function. This...

CVE-2025-13408

The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or...

CVE-2025-13366

The Rabbit Hole plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the plugin’s reset functionality....

CVE-2025-13363

The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the URL structure settings update functionality....

CVE-2025-13334

The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the “blaze_demo_importer_install_demo” function in all versions up to, and including, 1.0.13....

CVE-2025-13320

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile...