Post

2025-11-11 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2025-10966curl - curlcurl’s code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.CNA n/a CVSS3.1: 4.3 - MEDIUM0 1 2Exploitation: noneAutomatable: noTechnical Impact: partialmissing SFTP host verification with wolfSSHgithub
CVE-2025-12064f1logic - WP2Social Auto PublishThe WP2Social Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.CVSS3.1: 6.1 - MEDIUM0 1Exploitation: noneAutomatable: noTechnical Impact: partialWP2Social Auto Publish <= 2.4.7 - Reflected Cross-Site Scripting via PostMessagegithub
CVE-2025-11448smub - Gallery Plugin for WordPress – Envira Photo GalleryThe Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘/envira-convert/v1/bulk-convert’ REST API endpoint in all versions up to, and including, 1.11.0. This makes it possible for authenticated attackers, with contributor-level access and above, to convert galleries to Envira galleries.CVSS3.1: 4.3 - MEDIUM0 1Exploitation: noneAutomatable: noTechnical Impact: partialGallery Plugin for WordPress – Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery Conversiongithub
This post is licensed under CC BY 4.0 by the author.