Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Craig Webb

#19229of 53,633
13.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-43713
6.4
2025-10-25
WordPress · Listeo · CVE-2025-8413
**Name of the Vulnerable Software and Affected Versions** Listeo versions prior to 2.0.9 **Description** The Listeo theme for WordPress is susceptible to Stored Cross-Site Scripting through the `soundcloud` shortcode. Insufficient input sanitization and output escaping on user-supplied attributes allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages. These scripts will execute when a user accesses the affected page. The vulnerable component is the `soundcloud` shortcode. **Recommendations** Update Listeo to version 2.0.9 or later.
PT-2025-40491
7.5
2025-10-03
WordPress · Wp Dispatcher · CVE-2025-9212
**Name of the Vulnerable Software and Affected Versions** WP Dispatcher plugin for WordPress versions prior to 1.2.1 **Description** The WP Dispatcher plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation within the `wp dispatcher process upload()` function. This allows authenticated attackers with Subscriber-level access or higher to upload arbitrary files to the server. While an .htaccess file exists to limit the ability to achieve remote code execution, the possibility remains. **Recommendations** Update the WP Dispatcher plugin to version 1.2.1 or later.