CrossSite Request Forgery to Account Takeover via change_password() Function vulnerability
30 September, 2025
Unauthenticated Authentication Bypass via load_step Function vulnerability
30 September, 2025
Authenticated (Administrator+) Stored CrossSite Scripting vulnerability
30 September, 2025
Authenticated (Contributor+) Stored CrossSite Scripting via Shortcode vulnerability
30 September, 2025
Unauthenticated LFI vulnerability
13 August, 2025