Javo Core [javo-core] <= 3.0.0.529 (unfixed)
unknown
[en] Missing Authorization vulnerability in javothemes Javo Core javo-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Javo Core: from n/a through <= 3.0.0.529.
- Affected:
- up to 3.0.0.529
- Fix:
- No patched version reported
- Disclosed:
- Dec 18, 2025
CVE-2025-58877 on NVD →
Javo Core [javo-core] <= 3.0.0.266 (unfixed)
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code Injection.This issue affects Javo Core: from n/a through <= 3.0.0.266.
- Affected:
- up to 3.0.0.266
- Fix:
- No patched version reported
- Disclosed:
- Dec 18, 2025
CVE-2025-60068 on NVD →
Javo Core <= 3.0.0.266 - Cross-Site Request Forgery
medium
The Javo Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.0.266. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can tri...
- CVSS:
- 4.3
- Affected:
- up to 3.0.0.266
- Fix:
- No patched version reported
- Disclosed:
- Sep 26, 2025
CVE-2025-60111 on NVD →
Javo Core <= 3.0.0.266 - Missing Authorization
medium
The Javo Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.0.266. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 6.5
- Affected:
- up to 3.0.0.266
- Fix:
- No patched version reported
- Disclosed:
- Sep 22, 2025
CVE-2025-58003 on NVD →
Javo Core <= 3.0.0.529 - Unauthenticated Arbitrary Content Deletion
medium
The Javo Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.0.0.529. This makes it possible for unauthenticated attackers to delete arbitrary content.
- CVSS:
- 5.3
- Affected:
- up to 3.0.0.529
- Fix:
- No patched version reported
- Disclosed:
- Aug 26, 2025
CVE-2025-58877 on NVD →
Javo Core <= 3.0.0.266 - Unauthenticated Remote Code Execution
critical
The Javo Core plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.0.0.266. This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 3.0.0.266
- Fix:
- No patched version reported
- Disclosed:
- Aug 3, 2025
CVE-2025-60068 on NVD →
Javo Core <= 3.0.0.080 - Unauthenticated Privilege Escalation in ajax_signup
critical
The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an accou...
- CVSS:
- 9.8
- Affected:
- up to 3.0.0.080
- Fixed in:
- 3.0.0.266
- Disclosed:
- Mar 7, 2025
CVE-2025-0177 on NVD →
Javo Core [javo-core] < 3.0.0.266
unknown
- Affected:
- up to 3.0.0.266
- Fixed in:
- 3.0.0.266
CVE-2025-0177 on NVD →
Javo Core [javo-core] <= 3.0.0.266 (unfixed)
unknown
- Affected:
- up to 3.0.0.266
- Fix:
- No patched version reported
CVE-2025-60111 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database