by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors CVE-2026-1565 is a High-severity vulnerability (CVSS 8.8, CVE record) affecting the WordPress plugin User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration (slug: wp-user-frontend) in versions up to and...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors CVE-2024-37275 is a Medium-severity reflected cross-site scripting (XSS) vulnerability affecting NextScripts: Social Networks Auto-Poster (WordPress plugin slug: social-networks-auto-poster-facebook-twitter-g) in versions up to and including 4.4.6. The...
by Ivan Sorkin | Feb 25, 2026 | Themes
Attack Vectors The Restricted Site Access WordPress plugin (restricted-site-access) has a Medium severity issue (CVSS 5.3) that can be exploited over the network without login credentials. In affected versions (up to and including 6.3.0), an attacker may be able to...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2023-47654 is a Medium-severity (CVSS 6.4) Stored Cross-Site Scripting (XSS) vulnerability affecting the BZScore – Live Score WordPress plugin (slug: bzscore-live-score) in versions 1.03 and earlier. The key attack path is through the plugin’s...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Ninja Popups (WordPress plugin slug: arscode-ninja-popups) is affected by a Medium-severity Open Redirect vulnerability (CVE-2022-27861) in versions up to, and including, 4.7.7 (CVSS 4.3). This issue can be exploited by unauthenticated attackers by...
Recent Comments