| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-4520 | Uncanny Automator <= 6.4.0.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update | uncannyowl | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | Medium | 5.4 | 2025-05-14 02:23:18 | Deep Dive |
| CVE-2025-3623 | Uncanny Automator <= 6.4.0.1 - Unauthenticated PHP Object Injection in automator_api_decode_message Function | uncannyowl | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | Critical | 9.1 | 2025-05-14 02:23:17 | Deep Dive |
| CVE-2025-3794 | WPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter | smub | WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More | Medium | 5.4 | 2025-05-09 22:22:13 | Deep Dive |
| CVE-2025-47623 | WordPress Easy PayPal Buy Now Button plugin <= 2.0 - Cross Site Scripting (XSS) Vulnerability | Scott Paterson | Easy PayPal Buy Now Button | Medium | 5.9 | 2025-05-07 14:20:35 | Deep Dive |
| CVE-2025-47519 | WordPress Easy PayPal Events plugin <= 1.2.2 - Cross Site Request Forgery (CSRF) Vulnerability | Scott Paterson | Easy PayPal Events | Medium | 4.3 | 2025-05-07 14:20:06 | Deep Dive |
| CVE-2025-47483 | WordPress Easy Replace Image plugin <= 3.5.0 - Server Side Request Forgery (SSRF) Vulnerability | Iulia Cazan | Easy Replace Image | Medium | 4.9 | 2025-05-07 14:19:49 | Deep Dive |
| CVE-2025-27285 | WordPress Easy Form by AYS Plugin <= 2.6.9 - Reflected Cross Site Scripting (XSS) vulnerability | Ays Pro | Easy Form | High | 7.1 | 2025-04-17 15:48:09 | Deep Dive |
| CVE-2025-32562 | WordPress WP Easy Poll Plugin <= 2.2.9 - Reflected Cross Site Scripting (XSS) vulnerability | aviplugins.com | WP Easy Poll | High | 7.1 | 2025-04-17 15:47:29 | Deep Dive |
| CVE-2025-30970 | WordPress Easy Contact plugin <= 0.1.2 - Reflected Cross Site Scripting (XSS) vulnerability | scottwallick | Easy Contact | High | 7.1 | 2025-04-15 21:53:15 | Deep Dive |
| CVE-2025-2841 | Cart66 Cloud <= 2.3.7 - Unauthenticated Information Exposure | reality66 | Cart66 Cloud :: WordPress Ecommerce The Easy Way | Medium | 5.3 | 2025-04-12 02:23:15 | Deep Dive |
| CVE-2025-32567 | WordPress Easy Post Duplicator Plugin <= 1.0.1 - SQL Injection vulnerability | dev02ali | Easy Post Duplicator | High | 8.5 | 2025-04-11 08:42:57 | Deep Dive |
| CVE-2025-32538 | WordPress Easy Post Duplicator Plugin <= 1.0.1 - Reflected Cross Site Scripting (XSS) vulnerability | dev02ali | Easy Post Duplicator | High | 7.1 | 2025-04-11 08:42:55 | Deep Dive |
| CVE-2025-31395 | WordPress Easy Custom CSS plugin <= 1.0 - CSRF to Stored XSS vulnerability | a.ankit | Easy Custom CSS | High | 7.1 | 2025-04-09 16:10:01 | Deep Dive |
| CVE-2025-32477 | WordPress WP-Easy Menu plugin <= 0.41 - CSRF to Stored XSS vulnerability | Jordi Salord | WP-Easy Menu | High | 7.1 | 2025-04-09 16:09:56 | Deep Dive |
| CVE-2025-32147 | WordPress Easy WP Optimizer Plugin <= 1.1.0 - Broken Access Control vulnerability | coothemes | Easy WP Optimizer | High | 8.8 | 2025-04-04 15:58:35 | Deep Dive |
| CVE-2025-32138 | WordPress Easy Google Maps plugin <= 1.11.18 - XML External Entity vulnerability | supsystic | Easy Google Maps | Medium | 6.6 | 2025-04-04 15:58:32 | Deep Dive |
| CVE-2025-32120 | WordPress Easy Query – WP Query Builder plugin <= 2.0.4 - SQL Injection Vulnerability | edanzer | Easy Query – WP Query Builder | High | 7.6 | 2025-04-04 15:58:21 | Deep Dive |
| CVE-2025-2075 | Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation | uncannyowl | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | High | 8.8 | 2025-04-04 04:21:22 | Deep Dive |
| CVE-2025-31828 | WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | alextselegidis | Easy!Appointments | Medium | 4.3 | 2025-04-01 14:51:49 | Deep Dive |
| CVE-2025-31741 | WordPress Easy Magazine plugin <= 2.1.13 - Cross Site Scripting (XSS) vulnerability | Filtr8 | Easy Magazine | Medium | 6.5 | 2025-04-01 14:51:06 | Deep Dive |