浏览 26+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-53258 | WordPress Hover Effects plugin <= 2.1.2 - SQL Injection Vulnerability | Wow-Company | Hover Effects | High | 7.6 | 2025-06-27 13:21:06 | Deep Dive |
| CVE-2025-30912 | WordPress Float menu plugin <= 6.1.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | Wow-Company | Float menu | Medium | 5.4 | 2025-03-27 10:55:54 | Deep Dive |
| CVE-2025-26760 | WordPress Calculator Builder plugin <= 1.6.2 - Local File Inclusion vulnerability | Wow-Company | Calculator Builder | 高危 | - | 2025-02-22 15:52:47 | Deep Dive |
| CVE-2025-24699 | WordPress WP Coder Plugin <= 3.6 - CSRF to Cross Site Scripting (XSS) vulnerability | Wow-Company | WP Coder | High | 7.1 | 2025-02-14 12:44:36 | Deep Dive |
| CVE-2025-24724 | WordPress Side Menu Lite Plugin <= 5.3.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | Wow-Company | Side Menu Lite | Medium | 5.4 | 2025-01-24 17:25:11 | Deep Dive |
| CVE-2025-24716 | WordPress Herd Effects Plugin <= 6.2.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | Wow-Company | Herd Effects | Medium | 5.4 | 2025-01-24 17:25:09 | Deep Dive |
| CVE-2025-24717 | WordPress Modal Window Plugin <= 6.1.4 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | Wow-Company | Modal Window | Medium | 5.4 | 2025-01-24 17:25:08 | Deep Dive |
| CVE-2025-24715 | WordPress Counter Box Plugin <= 2.0.5 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | Wow-Company | Counter Box | Medium | 5.4 | 2025-01-24 17:25:06 | Deep Dive |
| CVE-2025-24713 | WordPress Button Generator – easily Button Builder Plugin <= 3.1.1 - Cross Site Request Forgery (CSRF) vulnerability | Wow-Company | Button Generator – easily Button Builder | Medium | 5.4 | 2025-01-24 17:25:06 | Deep Dive |
| CVE-2025-24720 | WordPress Sticky Buttons Plugin <= 4.1.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | Wow-Company | Sticky Buttons | Medium | 5.4 | 2025-01-24 17:25:05 | Deep Dive |
| CVE-2025-24714 | WordPress Bubble Menu Plugin <= 4.0.2 - Cross Site Request Forgery (CSRF) vulnerability | Wow-Company | Bubble Menu – circle floating menu | Medium | 5.4 | 2025-01-24 17:25:00 | Deep Dive |
| CVE-2025-24711 | WordPress Popup Box Plugin <= 3.2.4 - Cross Site Request Forgery (CSRF) vulnerability | Wow-Company | Popup Box | Medium | 5.4 | 2025-01-24 17:25:00 | Deep Dive |
| CVE-2023-49154 | WordPress Button Generator – easily Button Builder plugin <= 2.3.8 - Broken Access Control vulnerability | Wow-Company | Button Generator – easily Button Builder | Medium | 5.3 | 2024-12-09 11:30:23 | Deep Dive |
| CVE-2024-43346 | WordPress Modal Window – create popup modal window plugin <= 6.0.3 - Cross Site Scripting (XSS) vulnerability | Wow-Company | Modal Window | Medium | 6.5 | 2024-08-18 13:18:38 | Deep Dive |
| CVE-2024-35634 | Woocommerce – Recent Purchases plugin <= 1.0.1 - File Inclusion vulnerability | Wow-Company | Woocommerce – Recent Purchases | Medium | 4.9 | 2024-06-04 13:36:40 | Deep Dive |
| CVE-2024-35629 | WordPress Easy Digital Downloads – Recent Purchases plugin <= 1.0.2 - Remote File Inclusion vulnerability | Wow-Company | Easy Digital Downloads – Recent Purchases | Critical | 9.6 | 2024-06-04 13:34:27 | Deep Dive |
| CVE-2023-52149 | WordPress Floating Button Plugin <= 6.0 is vulnerable to Cross Site Request Forgery (CSRF) | Wow-Company | Floating Button | Medium | 5.4 | 2024-01-05 08:10:09 | Deep Dive |
| CVE-2023-49155 | WordPress Button Generator – easily Button Builder Plugin <= 2.3.8 is vulnerable to Cross Site Request Forgery (CSRF) | Wow-Company | Button Generator – easily Button Builder | Medium | 4.3 | 2023-12-18 22:13:32 | Deep Dive |
| CVE-2023-27418 | WordPress Side Menu Lite Plugin <= 4.0 is vulnerable to Cross Site Request Forgery (CSRF) | Wow-Company | Side Menu Lite – add sticky fixed buttons | Medium | 4.3 | 2023-11-12 22:53:01 | Deep Dive |
| CVE-2023-25443 | WordPress Button Generator – easily Button Builder Plugin <= 2.3.5 is vulnerable to Cross Site Request Forgery (CSRF) | Wow-Company | Button Generator – easily Button Builder | Medium | 4.3 | 2023-07-11 12:29:48 | Deep Dive |