| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-55038 | AutomationDirect CLICK PLUS Missing Authorization | AutomationDirect | CLICK PLUS C0-0x CPU firmware | Medium | 6.8 | 2025-09-23 22:24:29 | Deep Dive |
| CVE-2025-58473 | AutomationDirect CLICK PLUS Improper Resource Shutdown or Release | AutomationDirect | CLICK PLUS C0-0x CPU firmware | Medium | 5.9 | 2025-09-23 22:21:06 | Deep Dive |
| CVE-2025-55069 | AutomationDirect CLICK PLUS Predictable Seed in Pseudo-Random Number Generator | AutomationDirect | CLICK PLUS C0-0x CPU firmware | High | 8.3 | 2025-09-23 22:15:47 | Deep Dive |
| CVE-2025-59484 | AutomationDirect CLICK PLUS Use of a Broken or Risky Cryptographic Algorithm | AutomationDirect | CLICK PLUS C0-0x CPU firmware | High | 8.3 | 2025-09-23 22:08:41 | Deep Dive |
| CVE-2025-58069 | AutomationDirect CLICK PLUS Use of Hard-coded Cryptographic Key | AutomationDirect | CLICK PLUS C0-0x CPU firmware | Medium | 5.3 | 2025-09-23 22:04:58 | Deep Dive |
| CVE-2025-54855 | AutomationDirect CLICK PLUS Cleartext Storage of Sensitive Information | AutomationDirect | CLICK PLUS C0-0x CPU firmware | Medium | 4.2 | 2025-09-23 22:01:26 | Deep Dive |
| CVE-2025-58682 | WordPress Kama Click Counter plugin <= 4.0.4 - Cross Site Scripting (XSS) vulnerability | Timur Kamaev | Kama Click Counter | Medium | 6.5 | 2025-09-22 18:22:47 | Deep Dive |
| CVE-2025-10002 | ClickWhale <= 2.5.0 - Authenticated (Admin+) SQL injection | clickwhale | ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages | Medium | 4.9 | 2025-09-20 04:27:56 | Deep Dive |
| CVE-2025-8047 | Multiple Plugins from itayamar - Supply Chain Compromise | Unknown | disable-right-click-powered-by-pixterme | - | - | 2025-08-14 09:53:17 | Deep Dive |
| CVE-2025-28983 | WordPress Click & Pledge Connect plugin <= 25.04010101-WP6.8 - Privilege Escalation via SQL Injection vulnerability | ClickandPledge | Click & Pledge Connect | Critical | 9.8 | 2025-07-04 11:18:08 | Deep Dive |
| CVE-2025-49861 | WordPress Kama Click Counter plugin <= 4.0.3 - Cross Site Scripting (XSS) vulnerability | Timur Kamaev | Kama Click Counter | Medium | 6.5 | 2025-06-17 15:01:19 | Deep Dive |
| CVE-2025-5336 | Click to Chat <= 4.22 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via data-no_number Parameter | holithemes | Click to Chat – HoliThemes | Medium | 6.4 | 2025-06-14 08:23:26 | Deep Dive |
| CVE-2025-39411 | WordPress WhatsApp Click to Chat Plugin for WordPress plugin <= 2.2.12 - Local File Inclusion vulnerability | Indie_Plugins | WhatsApp Click to Chat Plugin for WordPress | High | 7.5 | 2025-05-19 18:58:02 | Deep Dive |
| CVE-2025-3455 | 1 Click WordPress Migration Plugin – 100% FREE for a limited time <= 2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload | 1clickmigration | 1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy Clone | High | 8.8 | 2025-05-09 06:42:36 | Deep Dive |
| CVE-2025-39548 | WordPress Right Click Disable OR Ban plugin <= 1.1.17 - CSRF to Stored XSS vulnerability | A WP Life | Right Click Disable OR Ban | High | 7.1 | 2025-04-16 12:44:38 | Deep Dive |
| CVE-2025-2636 | InstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File Inclusion | instawp | InstaWP Connect – 1-click WP Staging & Migration | High | 8.1 | 2025-04-11 04:21:31 | Deep Dive |
| CVE-2025-32550 | WordPress Click & Pledge Connect Plugin Plugin <= 2.24080000-WP6.6.1 - SQL Injection vulnerability | ClickandPledge | Click & Pledge Connect | High | 7.2 | 2025-04-09 16:09:39 | Deep Dive |
| CVE-2025-32257 | WordPress 1 Click WordPress Migration plugin <= 2.6.1 - Sensitive Data Exposure vulnerability | 1clickmigration | 1 Click WordPress Migration | Medium | 5.3 | 2025-04-04 15:59:30 | Deep Dive |
| CVE-2025-32246 | WordPress 1-Click Backup & Restore Database plugin <= 1.0.3 - Broken Access Control Vulnerability | Tim Nguyen | 1-Click Backup & Restore Database | Medium | 5.4 | 2025-04-04 15:59:24 | Deep Dive |
| CVE-2025-31092 | WordPress Click to Chat – WP Support All-in-One Floating Widget plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability | Ninja Team | Click to Chat – WP Support All-in-One Floating Widget | Medium | 6.5 | 2025-03-27 23:21:02 | Deep Dive |