| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-24357 | WordPress WP Recipe Maker plugin <= 10.2.4 - Broken Access Control vulnerability | Brecht | WP Recipe Maker | Medium | 4.3 | 2026-01-22 16:52:44 | Deep Dive |
| CVE-2019-25297 | Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 Stored XSS | Assaf Parag | Poll, Survey & Quiz Maker Plugin by Opinion Stage | 中危 | - | 2026-01-16 20:14:10 | Deep Dive |
| CVE-2025-15527 | WP Recipe Maker <= 10.2.2 - Insecure Direct Object Reference to Sensitive Information Exposure | brechtvds | WP Recipe Maker | Medium | 4.3 | 2026-01-16 04:44:34 | Deep Dive |
| CVE-2025-14579 | Quiz Maker < 6.7.0.89 - Admin+ Stored XSS | Unknown | Quiz Maker | - | - | 2026-01-12 06:00:10 | Deep Dive |
| CVE-2025-68867 | WordPress Effect Maker plugin <= 1.2.1 - Cross Site Scripting (XSS) vulnerability | anibalwainstein | Effect Maker | 中危 | - | 2026-01-08 09:17:51 | Deep Dive |
| CVE-2025-9637 | Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 6.5 | 2026-01-06 09:20:59 | Deep Dive |
| CVE-2025-9318 | Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 6.5 | 2026-01-06 09:20:59 | Deep Dive |
| CVE-2025-9294 | Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 4.3 | 2026-01-06 08:21:49 | Deep Dive |
| CVE-2025-68594 | WordPress Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin <= 19.12.0 - Broken Access Control vulnerability | Opinion Stage | Poll, Survey & Quiz Maker Plugin by Opinion Stage | Medium | 5.3 | 2025-12-24 13:10:45 | Deep Dive |
| CVE-2025-14385 | WP Recipe Maker <= 10.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | brechtvds | WP Recipe Maker | Medium | 6.4 | 2025-12-17 04:31:32 | Deep Dive |
| CVE-2025-67595 | WordPress Quiz Maker plugin <= 6.7.0.82 - Cross Site Request Forgery (CSRF) vulnerability | Ays Pro | Quiz Maker | Medium | 4.3 | 2025-12-09 14:14:18 | Deep Dive |
| CVE-2025-13143 | Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnection | assafp | Quiz, Poll & Survey Maker by Opinion Stage | Medium | 4.3 | 2025-11-27 05:31:57 | Deep Dive |
| CVE-2025-12426 | Quiz Maker <= 6.7.0.80 - Unauthenticated Sensitive Information Exposure | ays-pro | Quiz Maker | Medium | 5.3 | 2025-11-19 04:28:19 | Deep Dive |
| CVE-2025-64276 | WordPress Survey Maker plugin <= 5.1.9.4 - Broken Access Control vulnerability | Ays Pro | Survey Maker | 中危 | - | 2025-11-13 09:24:32 | Deep Dive |
| CVE-2025-12620 | Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 6.0.7 - Authenticated (Administrator+) SQL Injection via `filterbyauthor` Parameter | ays-pro | Poll Maker – Versus Polls, Anonymous Polls, Image Polls | Medium | 4.9 | 2025-11-13 05:30:40 | Deep Dive |
| CVE-2025-12891 | Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Information Exposure | ays-pro | Survey Maker | Medium | 5.3 | 2025-11-13 04:28:01 | Deep Dive |
| CVE-2025-12892 | Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Limited Option Update | ays-pro | Survey Maker | Medium | 5.3 | 2025-11-13 03:27:38 | Deep Dive |
| CVE-2025-62914 | WordPress Effect Maker plugin <= 1.2.1 - Broken Access Control vulnerability | anibalwainstein | Effect Maker | Medium | 6.5 | 2025-11-06 15:56:02 | Deep Dive |
| CVE-2025-53214 | WordPress Sertifier Certificate & Badge Maker plugin <= 1.21 - Broken Access Control Vulnerability | sertifier | Sertifier Certificate & Badge Maker | Medium | 6.5 | 2025-11-06 15:53:58 | Deep Dive |
| CVE-2025-62941 | WordPress Events Maker by dFactory plugin <= 1.6.14 - Cross Site Scripting (XSS) vulnerability | dFactory | Events Maker by dFactory | Medium | 6.5 | 2025-10-27 01:34:06 | Deep Dive |