VulnSea

Daily digest

Saturday 18 October 2025

A quiet day: only 10 new CVEs against a recent average of about 76. Of those, 4 high. One arrived with exploitation evidence or public exploit code already attached.

10
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2025-9890High· 8.8
11mo ago

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible fo…

▾ TwilightEPSS 0.40%via NVD
CVE-2025-47410High· 8.8
11mo ago

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on …

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on …

▾ Twilightapache · geodeEPSS 0.36%via NVD
CVE-2025-5555High· 7.8
11mo ago

A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1

A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in the library wnport.sys of the component IOCTL Handler. Such manipulation leads to stack-based buffer overflow. Local ac…

▾ TwilightEPSS 0.23%via NVD
CVE-2025-11691High· 7.5
11mo ago

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PPOM_Meta::get_fields_by_id() function in all versions up to, and including, 33.0.15 due to insufficient escaping on th…

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PPOM_Meta::get_fields_by_id() function in all versions up to, and including, 33.0.15 due to insufficient escaping on th…

▾ TwilightEPSS 0.48%via NVD
CVE-2025-11926Medium· 4.4PoC
11mo ago

The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.12 due to insufficient input sanitization and output escaping

The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.12 due to insufficient input sanitization and output escaping. This makes it possible for…

▾ TwilightEPSS 0.30%via NVD
CVE-2025-9562Medium· 6.4
11mo ago

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escapin…

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escapin…

▾ SunlitEPSS 0.31%via NVD
CVE-2025-11741Medium· 5.3
11mo ago

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can b…

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can b…

▾ SunlitEPSS 0.34%via NVD
CVE-2025-11703Medium· 5.3
11mo ago

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying…

▾ SunlitEPSS 0.23%via NVD
CVE-2025-11256Medium· 5.3
11mo ago

The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.3.5

The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated …

▾ SunlitEPSS 0.38%via NVD
CVE-2025-10750Medium· 5.3
11mo ago

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to missing capability checks and authentication verification on the 'testUser' endp…

▾ SunlitEPSS 0.47%via NVD

Most-affected vendors

By CVEs published in the period.