漏洞列表 355639
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-66073
WordPress WP Webhooks plugin <= 3.3.8 - PHP Object Injection vulnerability
MEDIUM 6.5 2025-11-21
Cozmoslabs WP Webhooks
CVE NVD
CVE-2025-66072
WordPress UsersWP plugin <= 1.2.47 - Broken Access Control vulnerability
CRITICAL 9.8 2025-11-21
Stiofan UsersWP
CVE NVD
CVE-2025-66071
WordPress Custom Order Numbers for WooCommerce plugin <= 1.11.0 - Broken Access Control vulnerability
CRITICAL 9.8 2025-11-21
tychesoftwares Custom Order Numbers for WooCommerce
CVE NVD
CVE-2025-66069
WordPress PPOM for WooCommerce plugin <= 33.0.16 - Broken Access Control vulnerability
MEDIUM 4.3 2025-11-21
Themeisle PPOM for WooCommerce
CVE NVD
CVE-2025-66067
WordPress Funnel Builder by FunnelKit plugin <= 3.13.1.2 - Cross Site Scripting (XSS) vulnerability
MEDIUM 5.4 2025-11-21
FunnelKit Funnel Builder by FunnelKit
CVE NVD
CVE-2025-66066
WordPress Envo Extra plugin <= 1.9.11 - Cross Site Scripting (XSS) vulnerability
MEDIUM 6.1 2025-11-21
EnvoThemes Envo Extra
CVE NVD
CVE-2025-66065
WordPress Gutenverse plugin <= 3.2.1 - Broken Access Control vulnerability
MEDIUM 5.3 2025-11-21
Jegstudio Gutenverse
CVE NVD
CVE-2025-66064
WordPress Giveaways and Contests by RafflePress plugin <= 1.12.20 - Cross Site Request Forgery (CSRF) vulnerability
MEDIUM 5.3 2025-11-21
Syed Balkhi Giveaways and Contests by RafflePress
CVE NVD
CVE-2025-66063
WordPress WP Google Review Slider plugin <= 17.4 - Broken Access Control vulnerability
MEDIUM 5.4 2025-11-21
jgwhite33 WP Google Review Slider
CVE NVD
CVE-2025-66062
WordPress WP YouTube Lyte plugin <= 1.7.28 - Open Redirection vulnerability
LOW 3.7 2025-11-21
Frank Goossens WP YouTube Lyte
CVE NVD
CVE-2025-66061
WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Cross Site Request Forgery (CSRF) vulnerability
MEDIUM 4.3 2025-11-21
Craig Hewitt Seriously Simple Podcasting castos seriously_simple_podcasting
CVE NVD
CVE-2025-66060
WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Broken Access Control vulnerability
MEDIUM 5.3 2025-11-21
Craig Hewitt Seriously Simple Podcasting castos seriously_simple_podcasting
CVE NVD
CVE-2025-66059
WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Sensitive Data Exposure vulnerability
MEDIUM 5.3 2025-11-21
Craig Hewitt Seriously Simple Podcasting castos seriously_simple_podcasting
CVE NVD
CVE-2025-66057
WordPress Bold Page Builder plugin <= 5.5.2 - Cross Site Scripting (XSS) vulnerability
MEDIUM 6.3 2025-11-21
boldthemes Bold Page Builder
CVE NVD
CVE-2025-66056
WordPress Uncanny Automator plugin < 6.10.0 - Sensitive Data Exposure vulnerability
MEDIUM 4.3 2025-11-21
Uncanny Owl Uncanny Automator
CVE NVD
CVE-2025-66055
WordPress Email Subscribers & Newsletters plugin <= 5.9.10 - PHP Object Injection vulnerability
HIGH 7.2 2025-11-21
Icegram Email Subscribers & Newsletters
CVE NVD
CVE-2025-66053
WordPress Enfold theme <= 7.1.2 - Cross Site Scripting (XSS) vulnerability
MEDIUM 6.5 2025-11-21
Kriesi Enfold
CVE NVD
CVE-2025-10039
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.2.9 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'eh_crm_ticket_single_view_client'
MEDIUM 4.3 2025-11-21
elextensions ELEX WordPress HelpDesk & Customer Ticketing System elula wsdesk
CVE NVD
CVE-2025-12935
FluentCRM - Marketing Automation For WordPress <= 2.9.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluentcrm_content' Shortcode
MEDIUM 6.4 2025-11-21
techjewel FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
CVE NVD
CVE-2025-10054
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Role Removal
MEDIUM 5.3 2025-11-21
elextensions ELEX WordPress HelpDesk & Customer Ticketing System elula wsdesk
CVE NVD