by Ivan Sorkin | Feb 13, 2026 | Plugins
Attack Vectors Easy Voice Mail (WordPress plugin slug: easy-voice-mail) versions 1.2.5 and earlier are affected by a Medium-severity Stored Cross-Site Scripting (XSS) issue tracked as CVE-2026-1164 (CVSS 6.1). Based on the published details, the primary attack path...
by Ivan Sorkin | Feb 13, 2026 | Plugins
Attack Vectors CVE-2026-1983 affects the WordPress plugin SEATT: Simple Event Attendance (slug: simple-event-attendance) in all versions up to and including 1.5.0. The issue is a Medium-severity Cross-Site Request Forgery (CSRF) vulnerability (CVSS 4.3). In practical...
by Ivan Sorkin | Feb 13, 2026 | Plugins
Attack Vectors Yoast Duplicate Post (slug: duplicate-post) versions up to and including 3.2.3 have a Medium-severity (CVSS 5.5) Stored Cross-Site Scripting (XSS) vulnerability tracked as CVE-2019-25314. The key risk scenario is an authenticated, high-privilege user...
by Ivan Sorkin | Feb 13, 2026 | Plugins
Attack Vectors WP Last Modified Info (slug: wp-last-modified-info) has a Medium-severity vulnerability (CVE-2025-14608, CVSS 5.3) affecting versions up to and including 1.9.5. It involves an Insecure Direct Object Reference (IDOR) in an AJAX action called bulk_save,...
by Ivan Sorkin | Feb 13, 2026 | Plugins
Attack Vectors The vulnerability in Easy Form Builder by WhiteStudio — Drag & Drop Form Builder (WordPress plugin slug: easy-form-builder) affects versions up to and including 3.9.3 and is rated Medium severity (CVSS 5.3; CVE-2025-14067). It can be exploited...
Recent Comments