by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors CVE-2025-31928 is a medium-severity SQL Injection vulnerability (CVSS 6.5) affecting the WordPress plugin Multimedia Responsive Carousel with Image Video Audio Support (slug: multimedia-carousel) in versions 2.6.0 and below. The attack requires an...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors CVE-2025-31915 is a Medium-severity Cross-Site Request Forgery (CSRF) vulnerability (CVSS 5.4) affecting Pixel WordPress Form BuilderPlugin & Autoresponder (plugin slug: pixel-formbuilder) in versions <= 1.0.3. This type of attack typically...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors CVE-2025-39534 is a Medium-severity Stored Cross-Site Scripting (XSS) issue (CVSS 6.4, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N) affecting Ninja Tables Pro (slug: ninja-tables-pro) versions <= 5.0.17. It can be exploited by an authenticated...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors Premmerce Product Search for WooCommerce (slug: premmerce-search) versions up to and including 2.2.4 contain a Medium-severity Cross-Site Request Forgery (CSRF) vulnerability (CVSS 4.3; vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N), tracked as...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors CVE-2025-32296 is a Medium severity (CVSS 5.3) missing-authorization issue affecting Simple Link Directory Pro (WordPress plugin slug: qc-simple-link-directory) in all versions prior to 14.8.1. Because the weakness can be exploited without...
Recent Comments