| CVE-2025-13381 | AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Missing Authorization to Unauthenticated Media File Uploads | ays-pro | AI ChatBot with ChatGPT and Content Generator by AYS | Medium | 5.3 | 2025-11-27 09:27:50 | Deep Dive |
| CVE-2025-13378 | AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter | ays-pro | AI ChatBot with ChatGPT and Content Generator by AYS | Medium | 6.5 | 2025-11-27 09:27:48 | Deep Dive |
| CVE-2025-13380 | AI Engine for WordPress: ChatGPT, GPT Content Generator <= 1.0.1 - Authenticated (Contributor+) Arbitrary File Read | liquidthemes | AI Engine for WordPress: ChatGPT, GPT Content Generator | Medium | 6.5 | 2025-11-25 07:28:25 | Deep Dive |
| CVE-2025-13583 | code-projects Question Paper Generator POST Parameter signupscript.php sql injection | code-projects | Question Paper Generator | High | 7.3 | 2025-11-24 04:32:05 | Deep Dive |
| CVE-2025-12973 | S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.8 - Authenticated (Editor+) Arbitrary File Upload | oc3dots | S2B AI Assistant – ChatBot, AI Agents, ChatGPT API, Image Generator | High | 7.2 | 2025-11-21 16:28:14 | Deep Dive |
| CVE-2025-12089 | Data Tables Generator by Supsystic <= 1.10.45 - Authenticated (Admin+) Arbitrary File Deletion | supsysticcom | Data Tables Generator by Supsystic | Medium | 6.5 | 2025-11-13 03:27:37 | Deep Dive |
| CVE-2025-12113 | Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images <= 1.8.3 - Missing Authorization to Authenticated (Subscriber+) API Key Deletion | webtoffee | Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images | Medium | 4.3 | 2025-11-12 07:27:41 | Deep Dive |
| CVE-2025-62039 | WordPress AI ChatBot with ChatGPT and Content Generator by AYS plugin <= 2.6.6 - Sensitive Data Exposure vulnerability | Ays Pro | AI ChatBot with ChatGPT and Content Generator by AYS | 中危 | - | 2025-11-06 15:55:37 | Deep Dive |
| CVE-2025-58207 | WordPress Ai Image Alt Text Generator for WP Plugin <= 1.1.5 - Broken Access Control Vulnerability | WP Messiah | Ai Image Alt Text Generator for WP | High | 8.2 | 2025-11-06 15:54:19 | Deep Dive |
| CVE-2025-11816 | Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.5.1 - Missing Authorization to Unauthenticated API Disconnect | wplegalpages | Privacy Policy Generator – WPLP Legal Pages | Medium | 5.3 | 2025-11-01 01:47:40 | Deep Dive |
| CVE-2025-62009 | WordPress UPC/EAN/GTIN Code Generator plugin <= 2.0.2 - Cross Site Request Forgery (CSRF) vulnerability | Dmitry V. (CEO of "UKR Solution") | UPC/EAN/GTIN Code Generator | Medium | 4.3 | 2025-10-22 14:32:49 | Deep Dive |
| CVE-2025-49945 | WordPress Shortcode Generator plugin <= 1.1 - Cross Site Scripting (XSS) vulnerability | kylegetson | Shortcode Generator | - | - | 2025-10-22 14:32:18 | Deep Dive |
| CVE-2025-10041 | Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload | ajitdas | Flex QR Code Generator | Critical | 9.8 | 2025-10-15 08:25:54 | Deep Dive |
| CVE-2025-10053 | TableGen – Data Table Generator <= 1.3.1 - Authenticated (Admin+) Stored Cross-Site Scripting | exlac | TableGen – Data Table Generator | Medium | 4.4 | 2025-10-03 11:17:16 | Deep Dive |
| CVE-2025-58268 | WordPress WPMK PDF Generator Plugin <= 1.0.1 - Cross Site Request Forgery (CSRF) Vulnerability | WPMK | WPMK PDF Generator | High | 7.1 | 2025-09-22 18:23:16 | Deep Dive |
| CVE-2025-58665 | WordPress Form Generator for WordPress Plugin <= 1.52 - Cross Site Scripting (XSS) Vulnerability | tmontg1 | Form Generator for WordPress | Medium | 5.9 | 2025-09-22 18:22:58 | Deep Dive |
| CVE-2025-8565 | Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.4.3 - Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Installation | wplegalpages | Privacy Policy Generator – WPLP Legal Pages | High | 8.1 | 2025-09-18 09:31:29 | Deep Dive |
| CVE-2025-58978 | WordPress PDF Generator for WordPress Plugin <= 1.5.4 - Broken Access Control Vulnerability | WP Swings | PDF Generator for WordPress | Medium | 5.3 | 2025-09-09 16:33:18 | Deep Dive |
| CVE-2025-53588 | WordPress UPC/EAN/GTIN Code Generator Plugin <= 2.0.2 - Arbitrary File Deletion Vulnerability | Dmitry V. (CEO of "UKR Solution") | UPC/EAN/GTIN Code Generator | High | 7.7 | 2025-08-28 12:37:33 | Deep Dive |
| CVE-2025-8621 | Mosaic Generator <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'c' Parameter | odn | Mosaic Generator | Medium | 6.4 | 2025-08-12 02:24:48 | Deep Dive |