| CVE-2025-60075 | WordPress hpb seo plugin for WordPress plugin <= 3.0.1 - Cross Site Request Forgery (CSRF) vulnerability | Allegro Marketing | hpb seo plugin for WordPress | - | - | 2025-10-29 08:38:03 | Deep Dive |
| CVE-2025-62912 | WordPress SiteGround Email Marketing plugin <= 1.7.1 - Cross Site Scripting (XSS) vulnerability | SiteGround | SiteGround Email Marketing | Medium | 6.5 | 2025-10-27 01:33:55 | Deep Dive |
| CVE-2025-11976 | FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Cross-Site Request Forgery to Sync Rule Creation | fusewp | FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) | Medium | 4.3 | 2025-10-25 06:49:25 | Deep Dive |
| CVE-2025-62481 | Oracle E-Business Suite 安全漏洞 | Oracle Corporation | Oracle Marketing | Critical | 9.8 | 2025-10-21 20:03:19 | Deep Dive |
| CVE-2025-53072 | Oracle E-Business Suite 安全漏洞 | Oracle Corporation | Oracle Marketing | Critical | 9.8 | 2025-10-21 20:03:08 | Deep Dive |
| CVE-2025-8902 | Widget Options - Extended <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | Marketing Fire, LLC | Widget Options - Extended | Medium | 6.4 | 2025-09-23 03:34:35 | Deep Dive |
| CVE-2025-57943 | WordPress Skimlinks Affiliate Marketing Tool plugin <= 1.3.1 - Server Side Request Forgery (SSRF) vulnerability | Skimlinks | Skimlinks Affiliate Marketing Tool | Medium | 4.4 | 2025-09-22 18:24:57 | Deep Dive |
| CVE-2025-57944 | WordPress Skimlinks Affiliate Marketing Tool plugin <= 1.3 - Broken Access Control vulnerability | Skimlinks | Skimlinks Affiliate Marketing Tool | Medium | 5.3 | 2025-09-22 18:24:56 | Deep Dive |
| CVE-2025-7654 | Multiple Plugins By FunnelKit <= (Various Versions) - Authenticated (Contributor+) Sensitive Information Exposure to Privilege Escalation via Woofunnel Library | amans2k | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | High | 8.8 | 2025-08-19 07:26:28 | Deep Dive |
| CVE-2025-52829 | WordPress DirectIQ Email Marketing plugin <= 2.0 - SQL Injection Vulnerability | DirectIQ | DirectIQ Email Marketing | Critical | 9.3 | 2025-06-27 11:52:14 | Deep Dive |
| CVE-2025-1562 | Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation | amans2k | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | Critical | 9.8 | 2025-06-18 07:22:44 | Deep Dive |
| CVE-2025-5938 | Digital Marketing and Agency Templates Addons for Elementor <= 1.1.1 - Cross-Site Request Forgery to Import | themebon | Digital Marketing and Agency Templates Addons for Elementor | Medium | 5.3 | 2025-06-13 01:47:51 | Deep Dive |
| CVE-2023-7197 | Marketing Twitter Bot <= 1.11 - Settings Update to Stored XSS via CSRF | Unknown | Marketing Twitter Bot | - | - | 2025-05-15 20:09:25 | Deep Dive |
| CVE-2025-4206 | WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg <= 4.1.1.2 - Authenticated (Administrator+) Arbitrary File Deletion | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | High | 7.2 | 2025-05-09 11:11:19 | Deep Dive |
| CVE-2025-47547 | WordPress SendPulse Email Marketing Newsletter plugin <= 2.1.6 - Cross Site Scripting (XSS) Vulnerability | SendPulse | SendPulse Email Marketing Newsletter | Medium | 6.5 | 2025-05-07 14:20:18 | Deep Dive |
| CVE-2025-31018 | WordPress FireDrum Email Marketing plugin <= 1.64 - Reflected Cross Site Scripting (XSS) vulnerability | FireDrum | FireDrum Email Marketing | High | 7.1 | 2025-04-17 15:47:52 | Deep Dive |
| CVE-2025-32608 | WordPress Movylo Marketing Automation Plugin <= 2.0.7 - Cross Site Scripting (XSS) vulnerability | Movylo | Movylo Marketing Automation | High | 7.1 | 2025-04-17 15:47:18 | Deep Dive |
| CVE-2025-39533 | WordPress Starfish Review Generation & Marketing plugin <= 3.1.19 - Privilege Escalation vulnerability | Starfish Reviews | Starfish Review Generation & Marketing | High | 8.8 | 2025-04-17 15:46:54 | Deep Dive |
| CVE-2025-39513 | WordPress ActiveDEMAND plugin <= 0.2.46 - Broken Access Control vulnerability | ActiveDEMAND Online Agency Marketing Automation | ActiveDEMAND | Medium | 5.3 | 2025-04-16 12:45:54 | Deep Dive |
| CVE-2025-31377 | WordPress Woo Product Feed For Marketing Channels plugin <= 1.9.0 - Broken Access Control Vulnerability | Asaquzzaman mishu | Woo Product Feed For Marketing Channels | High | 7.5 | 2025-04-09 16:10:09 | Deep Dive |