| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-31643 | WordPress WPCHURCH plugin <= 2.7.0 - Privilege Escalation Vulnerability | Dasinfomedia | WPCHURCH | High | 8.8 | 2026-01-07 12:05:18 | Deep Dive |
| CVE-2025-31642 | WordPress WPCHURCH plugin <= 2.7.0 - Reflected Cross Site Scripting (XSS) vulnerability | Dasinfomedia | WPCHURCH | High | 7.1 | 2026-01-06 21:14:53 | Deep Dive |
| CVE-2025-7049 | WPGYM - Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover | dasinfomedia | WPGYM - Wordpress Gym Management System | High | 8.8 | 2025-09-10 06:38:46 | Deep Dive |
| CVE-2025-6079 | School Management System <= 93.2.0 - Authenticated (Student+) Arbitrary File Upload | dasinfomedia | School Management System for Wordpress | High | 8.8 | 2025-08-16 03:38:53 | Deep Dive |
| CVE-2025-6080 | WPGYM <= 67.7.0 - Missing Authorization to Admin Account Creation | dasinfomedia | WPGYM - Wordpress Gym Management System | High | 8.8 | 2025-08-16 03:38:50 | Deep Dive |
| CVE-2025-3671 | WPGYM - Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update | dasinfomedia | WPGYM - Wordpress Gym Management System | High | 8.8 | 2025-08-16 03:38:49 | Deep Dive |
| CVE-2024-12612 | School Management System for Wordpress <= 93.2.0 - Unauthenticated SQL Injection | dasinfomedia | School Management System for Wordpress | High | 7.5 | 2025-08-16 03:38:47 | Deep Dive |
| CVE-2025-3740 | School Management System for Wordpress <= 93.1.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update | dasinfomedia | School Management System for Wordpress | High | 8.8 | 2025-07-18 04:23:00 | Deep Dive |
| CVE-2025-7442 | WPGYM - Wordpress Gym Management System < 67.8.0 - Unauthenticated SQL Injection | dasinfomedia | WPGYM - Wordpress Gym Management System | High | 7.5 | 2025-07-11 07:23:01 | Deep Dive |
| CVE-2024-12609 | School Management System for Wordpress <= 92.0.0 - Authenticated (Student+) SQL Injection via 'view-attendance' | dasinfomedia | School Management System for Wordpress | Medium | 6.5 | 2025-03-07 08:21:27 | Deep Dive |
| CVE-2024-9658 | School Management System for Wordpress <= 93.0.0 - Authenticated (Student+) Account Takeover and Privilege Escalation | dasinfomedia | School Management System for Wordpress | High | 8.8 | 2025-03-07 08:21:27 | Deep Dive |
| CVE-2024-12610 | School Management System for Wordpress <= 93.0.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion | dasinfomedia | School Management System for Wordpress | Medium | 5.3 | 2025-03-07 08:21:26 | Deep Dive |
| CVE-2024-12611 | School Management System for Wordpress <= 93.0.0 - Reflected Cross-Site Scripting | dasinfomedia | School Management System for Wordpress | Medium | 5.3 | 2025-03-07 08:21:24 | Deep Dive |
| CVE-2024-12607 | School Management System for Wordpress <= 92.0.0 - Authenticated (Subscriber+) SQL Injection via 'mj_smgt_show_event_task' | dasinfomedia | School Management System for Wordpress | Medium | 6.5 | 2025-03-07 08:21:21 | Deep Dive |
| CVE-2024-9659 | School Management <= 91.5.0 - Unauthenticated Arbitrary File Upload | dasinfomedia | School Management System for Wordpress | Critical | 9.8 | 2024-11-23 07:38:08 | Deep Dive |
| CVE-2024-9941 | WPGYM <= 67.1.0 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation | dasinfomedia | WPGYM - Wordpress Gym Management System | High | 8.8 | 2024-11-23 07:38:07 | Deep Dive |
| CVE-2024-9942 | WPGYM <= 67.1.0 - Unauthenticated Arbitrary File Upload | dasinfomedia | WPGYM - Wordpress Gym Management System | Critical | 9.8 | 2024-11-23 07:38:06 | Deep Dive |
| CVE-2024-9660 | School Management <= 91.5.0 - Authenticated (Student+) Arbitrary File Upload | dasinfomedia | School Management System for Wordpress | High | 8.8 | 2024-11-23 07:38:04 | Deep Dive |