Slider & Popup Builder by Depicter CVE-2025-2011: Unauthenticated SQL Injection (100,000+ Sites, CVSS 9.3)
CVE-2025-2011 is a critical unauthenticated SQL injection in Slider & Popup Builder by Depicter (versions up to 3.6.1)…
Security vulnerability reports and CVE analysis for WordPress plugins, themes, and core.
CVE-2025-2011 is a critical unauthenticated SQL injection in Slider & Popup Builder by Depicter (versions up to 3.6.1)…
CVE-2024-2876 is a critical unauthenticated SQL injection flaw in the popular Email Subscribers by Icegram Express plugin, scoring…
NotificationX, the popular FOMO and social-proof plugin for WordPress, contained an unauthenticated SQL injection flaw (CVE-2024-1698, CVSS 9.8)…
A critical flaw in the Alone – Charity Multipurpose Non-profit WordPress theme (CVE-2025-5394, CVSS 9.8) let unauthenticated attackers…
A critical flaw (CVE-2024-6695, CVSS 9.8) in the Profile Builder plugin let unauthenticated attackers register their way into…
A critical flaw in the popular AI Engine plugin exposed a secret Bearer Token through an unauthenticated REST…
CVE-2025-4322 is a critical flaw in the premium Motors WordPress theme that let unauthenticated attackers reset any user's…
A missing file-type check in Modern Events Calendar (CVE-2024-5441, CVSS 8.8) let low-privileged and even unauthenticated users upload…
A critical flaw in Widget Options, a WordPress plugin on 100,000+ sites, let any Contributor-level user run arbitrary…
A critical flaw in WP Ghost (Hide My WP Ghost), a WordPress security plugin with over 200,000 installs,…