by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors CVE-2026-27542 is a Critical vulnerability (CVSS 9.8, vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) affecting the Wholesale Lead Capture Plugin for WooCommerce (slug: woocommerce-wholesale-lead-capture) in all versions up to and including...
by Ivan Sorkin | Feb 26, 2026 | Themes
Attack Vectors Kiamo – Responsive Business Service WordPress Theme (slug: kiamo) has a Critical vulnerability (CVE-2025-31633, CVSS 9.8) that can be exploited remotely by an attacker with no login required. Because this is an Unauthenticated Local File Inclusion...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors WPZOOM Addons for Elementor – Starter Templates & Widgets (slug: wpzoom-elementor-addons) has a Medium severity vulnerability (CVSS 6.1, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) affecting versions up to and including 1.3.4. The issue is...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors CVE-2025-14149 is a medium-severity Stored Cross-Site Scripting (XSS) issue (CVSS 6.4) affecting the WordPress plugin Xpro Addons — 140+ Widgets for Elementor (slug: xpro-elementor-addons) in versions up to and including 1.4.24. The primary attack path...
by Ivan Sorkin | Feb 26, 2026 | Themes
Attack Vectors CVE-2025-14040 is a medium-severity Stored Cross-Site Scripting (XSS) issue (CVSS 6.4) affecting the Automotive Car Dealership Business WordPress Theme (slug: automotive) in versions 13.4 and earlier. An attacker must already have a WordPress account...
Recent Comments