General-Purpose System Vulnerabilities
Vulnerabilities related to traditional IT systems, servers, and desktop applications.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-14629 | The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capab… | Medium (5.3) | 2026-01-24 | General Purpose |
| CVE-2025-14609 | The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.… | Medium (5.3) | 2026-01-24 | General Purpose |
| CVE-2025-13676 | The JustClick registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … | Medium (6.1) | 2026-01-24 | General Purpose |
| CVE-2025-13374 | The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | Critical (9.8) | 2026-01-24 | General Purpose |
| CVE-2025-12836 | The VK Google Job Posting Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Descrip… | Medium (6.4) | 2026-01-24 | General Purpose |