tag
Nonce
Critical
WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
CVE-2025-12057·
WavePlayer (WordPress plugin)
unpatched
High
WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
CVE-2026-5415·
WP Captcha PRO (WordPress plugin, Advanced Google reCAPTCHA)
unpatched
High
Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
CVE-2026-11912·
Simple File List WordPress plugin
patched