30 New WordPress related vulnerabilities - April 28, 2025

30 New WordPress related vulnerabilities - April 28, 2025

List of newly disclosed WordPress-related vulnerabilities:

Plugin/Theme Vulnerability Summary CVSS CVE
aeropage–Aeropage Sync for Airtable Arbitrary file upload (RCE risk) 8.8 CVE-2025-3914
aonetheme–Service Finder Bookings Privilege escalation via social login 9.8 CVE-2025-2470
arkenon–Frontend Login and Registration Blocks Privilege escalation via password reset flaw 8.8 CVE-2025-3607
artbees–Jupiter X Core PHP Object Injection (potential for RCE if POP chain present) 8.1 CVE-2025-2105
cajka–Verification SMS with TargetSMS Remote code execution via callable functions 8.3 CVE-2025-3776
dorinabc–Create Custom Forms for WordPress Arbitrary shortcode execution 7.3 CVE-2025-2801
eyecix–JobSearch WP Job Board Authentication bypass via social login 8.1 CVE-2024-11917
felipe152–Integração entre Eduzz e WooCommerce Role escalation to administrator 8.8 CVE-2025-3906
jauharixelion–Xelion Webchat Privilege escalation via default role modification 8.8 CVE-2025-3058
joedolson–My Tickets Accessible Event Ticketing Privilege escalation 8.8 CVE-2025-3761
kiranpatil353–Add Custom Page Template PHP Code Injection (Admin level) 7.2 CVE-2025-3491
ludwigyou–WPMasterToolKit Directory traversal (Admin level) 7.2 CVE-2025-3300
mra13–WordPress Simple Shopping Cart Sensitive data exposure 8.2 CVE-2025-3529
mra13–WordPress Simple Shopping Cart Product price manipulation 7.5 CVE-2025-3530
neoslab–Database Toolset Arbitrary file deletion (possible RCE) 9.1 CVE-2025-3065
Odin_Design–Vikinger Privilege escalation via user meta 8.8 CVE-2025-2238
SeaTheme–BM Content Builder Privilege escalation via unauthorized option updates 8.8 CVE-2025-1279
TeconceTheme–Mayosis Core Arbitrary file read 7.5 CVE-2025-1565
ThemeMove–EduMall Theme Local file inclusion (LFI -> possible RCE) 8.1 CVE-2025-2101
v1rustyle–Flynax Bridge Password reset takeover 9.8 CVE-2025-3603
v1rustyle–Flynax Bridge Email change takeover 9.8 CVE-2025-3604
wp-configurator–Configurator Theme Core Privilege escalation 8.8 CVE-2025-3101
wpeverest–User Registration Reflected XSS 7.1 CVE-2025-39400
WPoperation–Arrival PHP Local File Inclusion (LFI) 7.5 CVE-2025-32921
WPoperation–Opstore PHP Local File Inclusion (LFI) 7.5 CVE-2025-39387
WPQuark–eForm Stored XSS 7.2 CVE-2025-1294
wpsoul–Greenshift Animation and Page Builder Blocks Arbitrary file upload 8.8 CVE-2025-3616
WPXpro–Xpro Elementor Addons - Pro Remote code execution via insecure widget 8.8 CVE-2024-13808
buildwps–Prevent Direct Access Protect WordPress Files Unauthorized file access 5.4 CVE-2025-3861
devitemsllc–ShopLentor SSRF vulnerability 6.5 CVE-2025-3775

Major WordPress Vulnerabilities Disclosed by CISA (April 28, 2025 Summary)

WordPress, being the world’s most popular content management system, continues to be a major target for cyberattacks. In the latest CISA vulnerability bulletin, 30 WordPress-related vulnerabilities have been disclosed. These flaws range from remote code execution (RCE) and privilege escalation to local file inclusion (LFI) and cross-site scripting (XSS).

Below, we detail the major vulnerabilities, beginning with the most critical based on CVSS score and real-world exploitation potential:


1. Privilege Escalation in Service Finder Bookings (CVE-2025-2470)


2. Privilege Escalation in Flynax Bridge (CVE-2025-3603 and CVE-2025-3604)


3. Arbitrary File Deletion via Database Toolset (CVE-2025-3065)


4. Remote Code Execution in Aeropage Sync for Airtable (CVE-2025-3914)


5. Remote Code Execution in Xpro Elementor Addons - Pro (CVE-2024-13808)


6. Arbitrary Password Change in Frontend Login and Registration Blocks (CVE-2025-3607)


7. Arbitrary Password Reset in Xelion Webchat (CVE-2025-3058)


8. Privilege Escalation via My Tickets Accessible Event Ticketing (CVE-2025-3761)


9. Privilege Escalation via BM Content Builder (CVE-2025-1279)


Other Notable WordPress Plugin Vulnerabilities:


⚙️ Recommendations for WordPress Site Owners

Thanks for Reading. You may also like some of these popular articles:


Critical Security Vulnerability in XAMPP for Windows
A critical security vulnerability has been identified in the default settings of the Apache service configuration within XAMPP on Windows systems. This flaw, discovered by Security Researcher Kaotickj, raises significant security concerns. [ Read ]


Proof of Concept for Learning Management System Exploits
While testing and confirming the above known exploits, Security Researcher, Johnny Watts, has found an additional arbitrary file upload flaw in the "classroom materials" upload function. The researcher was able to successfully upload a php command shell which he used to gain administrative access to the target system. [ Read ]


Frequently Asked Questions About Web Design
I’ve compiled this list of questions that I frequently get from clients and visitors to provide you with a better understanding of what Web Designers do, and how your Business can benefit from hiring a professional Web Designer. [ Read ]


6 Reasons Your Local Business Listings Need to Be Accurate
All local business listings for your business must be accurate! Incomplete or inaccurate information can be the deciding factor in a potential customer's decision between you and your competitor! [ Read ]


How to Respond to Negative Reviews
How you respond to a negative review impacts not only the reviewer, but all the sets of eyes that come afterward. Seeing a business handle a particularly challenging review online suggests that management is proud of their business, and willing to go the extra mile to maintain their reputation! [ Read ]


Critical Data For Online Business Listings
If you want to rank well in local search, you need consistent NAP data, website, hours, and more across all major listing directories. [ Read ]


How to Respond to Positive Reviews
While negative reviews often get this most attention, positive reviews are as or more important! Its important to respond to positive reviews to thank customers for taking the time to review your business and to encourage others to do the same. [ Read ]


The Basics of Online Advertising
Digital advertising increases awareness - its that simple. Digital advertising consists of a range of services, all of which work to promote a business online. [ Read ]


How to Engage Your Audience Through Social Media
Is your social media falling flat? Don't sweat it; many hours have gone into perfecting the use of this not-so-secret weapon. Facebook, Google+, Twitter, Pinterest, and Instagram strategies are outlined in detail below. [ Read ]


Understanding and Optimizing Your Website Speed
Page speed is the amount of time it takes for the content on a website's page to fully load. In a world where people have come to expect instantaneous results, faster is better. [ Read ]


 

An animated image representing bots being counted with the text: One bot. Two bots. Three bots. Four. Each one counts a little more. johnny5
johnny5
johnny5
johnny5