by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Image Map Pro – Drag-and-drop Builder for Interactive Images (slug: image-map-pro) versions below 5.6.9 are affected by a High-severity Cross-Site Request Forgery (CSRF) vulnerability (CVE-2022-45850, CVSS 8.8; vector:...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2023-27621 is a Medium severity (CVSS 4.4) Stored Cross-Site Scripting (Stored XSS) vulnerability affecting the Livestream Notice WordPress plugin (livestream-notice) in versions up to and including 1.2.0. The attack requires an authenticated user...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors The WordPress plugin Conditional Checkout Fields & Edit Checkout Fields for WooCommerce (slug: conditional-checkout-fields-for-woocommerce) is affected by CVE-2022-45070, a Medium severity issue (CVSS 5.3; vector:...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Cyklodev WP Notify (slug: cyklodev-wp-notify) is affected by CVE-2022-44625, a Medium severity Stored Cross-Site Scripting (XSS) issue (CVSS 5.5). The attack requires an authenticated WordPress user with Admin (or higher) privileges, meaning it is most...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors TypeSquare Webfonts for ConoHa (WordPress plugin slug: ts-webfonts-for-conoha) versions up to and including 2.0.3 contain a Medium-severity stored cross-site scripting (XSS) issue (CVE-2023-25458, CVSS 4.4). The attack requires an authenticated user...
Recent Comments