Tagged: Cybersecurity Alert

CVE-2025-62918

Missing Authorization vulnerability in ignitionwp IgnitionDeck ignitiondeck allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IgnitionDeck: from n/a through

CVE-2025-62919

Missing Authorization vulnerability in themeshopy TS Demo Importer ts-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TS Demo Importer: from n/a through

CVE-2025-62920

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in webnique USERCENTRICS CMP usercentrics-consent-management-platform allows Stored XSS.This issue affects USERCENTRICS CMP: from n/a through

CVE-2025-62921

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Pagup Bulk Auto Image Title Attribute bulk-image-title-attribute allows DOM-Based XSS.This issue affects Bulk Auto Image Title Attribute: from n/a through

CVE-2025-62922

Missing Authorization vulnerability in Shambhu Patnaik Export Categories export-categories allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export Categories: from n/a through

CVE-2025-62923

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Debuggers Studio Marquee Addons for Elementor marquee-addons-for-elementor allows DOM-Based XSS.This issue affects Marquee Addons for Elementor: from n/a through

CVE-2025-62910

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in deshine Video Gallery by Huzzaz huzzaz-video-gallery allows Stored XSS.This issue affects Video Gallery by Huzzaz: from n/a through

CVE-2025-62911

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Rock Content Rock Convert rock-convert allows Stored XSS.This issue affects Rock Convert: from n/a through

CVE-2025-62912

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through

CVE-2025-62913

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in wpopal Opal Service opal-service allows Stored XSS.This issue affects Opal Service: from n/a through

CVE-2025-62915

Missing Authorization vulnerability in clicksend SMS Contact Form 7 Notifications by ClickSend clicksend-contactform7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Contact Form 7 Notifications by ClickSend: from n/a through

CVE-2025-62907

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in aviplugins.com Custom Post Type Attachment custom-post-type-pdf-attachment allows Stored XSS.This issue affects Custom Post Type Attachment: from n/a through

CVE-2025-62908

Missing Authorization vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Podlove Web Player: from n/a through

CVE-2025-62909

Missing Authorization vulnerability in mrityunjay Smart WeTransfer smart-wetransfer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart WeTransfer: from n/a through