by Ivan Sorkin | Feb 27, 2026 | Plugins
Attack Vectors Tutor LMS – eLearning and online course solution (WordPress plugin slug: tutor) is affected by a High-severity vulnerability (CVSS 7.5) tracked as CVE-2025-13673. The issue is an unauthenticated SQL injection that can be triggered via the coupon_code...
by Ivan Sorkin | Feb 27, 2026 | Plugins
Attack Vectors WP Mail Logging (slug: wp-mail-logging) is affected by a High-severity vulnerability (CVE-2026-2471, CVSS 7.5) that can be triggered through everyday website interactions. An unauthenticated attacker may submit a specially crafted payload via any...
by Ivan Sorkin | Feb 27, 2026 | Plugins
Attack Vectors Administrator Z (slug: administrator-z) is affected by a medium-severity Cross-Site Request Forgery (CSRF) vulnerability (CVE-2025-32276) in all versions up to, and including, 2025.03.04. The most likely attack path is social engineering: an...
by Ivan Sorkin | Feb 27, 2026 | Plugins
Attack Vectors MailArchiver (WordPress plugin slug: mailarchiver) is affected by CVE-2026-2831, a Medium severity SQL Injection issue (CVSS 4.9, vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N). This vulnerability can be exploited by an authenticated user with...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors Electric Enquiries (slug: electric-enquiries) versions <= 1.1 have a medium-severity Stored Cross-Site Scripting (XSS) issue (CVE-2025-14142, CVSS 6.4) that can be exploited by an authenticated user with Contributor-level access or higher. The attack...
Recent Comments