Total
6931 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-66130 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in etruel WP Views Counter wpecounter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Views Counter: from n/a through <= 2.1.2.
|
|||||
| CVE-2025-66129 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pochipp: from n/a through <= 1.18.0.
|
|||||
| CVE-2025-66128 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Brevo Sendinblue for WooCommerce woocommerce-sendinblue-newsletter-subscription allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sendinblue for WooCommerce: from n/a through <= 4.0.49.
|
|||||
| CVE-2025-66127 | 2026-01-20 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Real Estate: from n/a through <= 5.2.2.
|
|||||
| CVE-2025-66124 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leaky Paywall: from n/a through <= 4.22.5.
|
|||||
| CVE-2025-66122 | 2026-01-20 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in Design Stylish Price List stylish-price-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stylish Price List: from n/a through <= 7.2.2.
|
|||||
| CVE-2025-66121 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in SiteGround SiteGround Security sg-security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SiteGround Security: from n/a through <= 1.5.8.
|
|||||
| CVE-2025-66120 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in CatFolders CatFolders catfolders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CatFolders: from n/a through <= 2.5.3.
|
|||||
| CVE-2025-66117 | 2026-01-20 | N/A | 7.5 HIGH | ||
|
Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form: from n/a through <= 2.7.8.
|
|||||
| CVE-2025-66114 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in theme funda Show Variations as Single Products Woocommerce woo-show-single-variations-shop-category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Show Variations as Single Products Woocommerce: from n/a through <= 2.0.
|
|||||
| CVE-2025-66113 | 2026-01-20 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in ThemeAtelier Better Chat Support for Messenger better-chat-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Chat Support for Messenger: from n/a through <= 1.2.18.
|
|||||
| CVE-2025-66112 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in WebToffee Accessibility Toolkit by WebYes accessibility-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Toolkit by WebYes: from n/a through <= 2.0.4.
|
|||||
| CVE-2025-66110 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tiktok Feed: from n/a through <= 1.0.22.
|
|||||
| CVE-2025-66109 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in octolize Cart Weight for WooCommerce woo-cart-weight allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cart Weight for WooCommerce: from n/a through <= 1.9.11.
|
|||||
| CVE-2025-66108 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TNC Toolbox: Web Performance: from n/a through <= 2.0.4.
|
|||||
| CVE-2025-66107 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7.
|
|||||
| CVE-2025-66106 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Essential Plugin Featured Post Creative featured-post-creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through <= 1.5.5.
|
|||||
| CVE-2025-66104 | 2026-01-20 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Offload, AI & Optimize with Cloudflare Images: from n/a through <= 1.9.5.
|
|||||
| CVE-2025-66101 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Sabuj Kundu CBX Bookmark & Favorite cbxwpbookmark allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CBX Bookmark & Favorite: from n/a through <= 2.0.1.
|
|||||
| CVE-2025-66100 | 2026-01-20 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.3.5.
|
|||||
| CVE-2025-66099 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chat Help: from n/a through <= 3.1.3.
|
|||||
| CVE-2025-66096 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Imtiaz Rayhan Table Block by Tableberg tableberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Table Block by Tableberg: from n/a through <= 0.6.9.
|
|||||
| CVE-2025-66089 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.1.
|
|||||
| CVE-2025-66088 | 2026-01-20 | N/A | 7.5 HIGH | ||
|
Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12.
|
|||||
| CVE-2025-66087 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12.
|
|||||
| CVE-2025-66086 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.8.
|
|||||
| CVE-2025-66085 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arconix Shortcodes: from n/a through <= 2.1.18.
|
|||||
| CVE-2025-66084 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentCommunity: from n/a through <= 2.0.0.
|
|||||
| CVE-2025-66083 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.
|
|||||
| CVE-2025-66082 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.
|
|||||
| CVE-2025-66080 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.0.3.
|
|||||
| CVE-2025-66077 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Legal Pages: from n/a through <= 1.4.6.
|
|||||
| CVE-2025-66075 | 2026-01-20 | N/A | 4.2 MEDIUM | ||
|
Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3.
|
|||||
| CVE-2025-66072 | 2026-01-20 | N/A | 9.8 CRITICAL | ||
|
Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47.
|
|||||
| CVE-2025-66070 | 2026-01-20 | N/A | 7.5 HIGH | ||
|
Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.10.
|
|||||
| CVE-2025-66069 | 2026-01-20 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Themeisle PPOM for WooCommerce woocommerce-product-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PPOM for WooCommerce: from n/a through <= 33.0.16.
|
|||||
| CVE-2025-66068 | 2026-01-20 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.1.9.
|
|||||
| CVE-2025-66065 | 2026-01-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Jegstudio Gutenverse gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n/a through <= 3.2.1.
|
|||||
| CVE-2025-66063 | 2026-01-20 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Google Review Slider: from n/a through <= 17.4.
|
|||||
| CVE-2025-66060 | 1 Castos | 1 Seriously Simple Podcasting | 2026-01-20 | N/A | 5.3 MEDIUM |
|
Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.
|
|||||