| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-3715 | Bold Page Builder <= 5.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-text' Parameter | boldthemes | Bold Page Builder | Medium | 6.4 | 2025-05-18 05:22:40 | Deep Dive |
| CVE-2023-5529 | Advanced Page Visit Counter <= 8.0.6 - Admin+ Stored XSS | Unknown | Advanced Page Visit Counter | - | - | 2025-05-15 20:08:59 | Deep Dive |
| CVE-2024-8618 | Page Builder: Pagelayer < 1.9.0- Admin+ Stored XSS | Unknown | Page Builder: Pagelayer | - | - | 2025-05-15 20:07:17 | Deep Dive |
| CVE-2024-8426 | Pagelayer < 1.8.8 - Admin+ Stored XSS | Unknown | Page Builder: Pagelayer | - | - | 2025-05-15 20:07:16 | Deep Dive |
| CVE-2024-11221 | Full Screen (Page) Background Image Slideshow <= 1.1 - Admin+ Stored XSS | Unknown | Full Screen (Page) Background Image Slideshow | - | - | 2025-05-15 20:06:48 | Deep Dive |
| CVE-2025-3949 | Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.18.15 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure | seedprod | Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode | Medium | 4.3 | 2025-05-09 08:24:05 | Deep Dive |
| CVE-2024-6648 | Path Traversal in AP Page Builder | Apollo Theme | AP Page Builder | - | - | 2025-05-08 12:16:53 | Deep Dive |
| CVE-2025-47593 | WordPress Really Simple Under Construction Page plugin <= 1.4.6 - Cross Site Scripting (XSS) Vulnerability | Jonas Hjalmarsson | Really Simple Under Construction Page | Medium | 5.9 | 2025-05-07 14:20:24 | Deep Dive |
| CVE-2025-47525 | WordPress Bold Page Builder plugin <= 5.3.0 - Cross Site Scripting (XSS) Vulnerability | boldthemes | Bold Page Builder | Medium | 5.9 | 2025-05-07 14:20:10 | Deep Dive |
| CVE-2025-47488 | WordPress Bold Page Builder plugin <= 5.3.2 - Cross Site Scripting (XSS) Vulnerability | boldthemes | Bold Page Builder | Medium | 6.5 | 2025-05-07 14:19:51 | Deep Dive |
| CVE-2025-2816 | Page View Count 2.8.0 - 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update | a3rev | Page View Count | High | 8.1 | 2025-05-01 02:23:03 | Deep Dive |
| CVE-2025-2893 | Gutenverse <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via countdown Block | jegstudio | Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem | Medium | 6.4 | 2025-04-29 06:37:47 | Deep Dive |
| CVE-2025-3491 | Add custom page template <= 2.0.1 - Authenticated (Administrator+) PHP Code Injection to Remote Code Execution | kiranpatil353 | Add custom page template | High | 7.2 | 2025-04-26 05:34:24 | Deep Dive |
| CVE-2025-46477 | WordPress WP Customize Login Page plugin <= 1.6.5 - Cross Site Scripting (XSS) Vulnerability | Carlo La Pera | WP Customize Login Page | Medium | 5.9 | 2025-04-24 16:09:21 | Deep Dive |
| CVE-2025-46485 | WordPress WP Customize Login Page plugin <= 1.6.5 - Broken Access Control Vulnerability | Carlo La Pera | WP Customize Login Page | Medium | 5.3 | 2025-04-24 16:09:21 | Deep Dive |
| CVE-2025-46521 | WordPress WS Force Login Page plugin <= 3.0.3 - Cross Site Scripting (XSS) Vulnerability | Silver Muru | WS Force Login Page | Medium | 5.9 | 2025-04-24 16:09:15 | Deep Dive |
| CVE-2025-46484 | WordPress Image Hover Effects For WPBakery Page Builder plugin <= 2.0 - Cross Site Scripting (XSS) Vulnerability | nasir179125 | Image Hover Effects For WPBakery Page Builder | Medium | 6.5 | 2025-04-24 16:08:50 | Deep Dive |
| CVE-2025-46225 | WordPress Post in page for Elementor plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability | Michael | Post in page for Elementor | Medium | 6.5 | 2025-04-22 09:53:19 | Deep Dive |
| CVE-2025-3616 | Greenshift 11.4 - 11.4.5 - Authenticated (Subscriber+) Arbitrary File Upload | wpsoul | Greenshift – animation and page builder blocks | High | 8.8 | 2025-04-22 04:21:33 | Deep Dive |
| CVE-2025-2010 | JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin <= 2.3.9 - Unauthenticated SQL Injection | mhmrajib | JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin | High | 7.5 | 2025-04-19 02:22:34 | Deep Dive |