by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2024-11719 affects the tarteaucitron.js for WordPress plugin (tarteaucitron-wp) in versions before 0.3.0. It is rated Medium severity (CVSS 6.1). The primary attack path is a forged request (Cross-Site Request Forgery) that relies on user...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2024-11718 is a Medium-severity Stored Cross-Site Scripting (XSS) issue (CVSS 6.4, vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N) affecting the tarteaucitron.js for WordPress plugin (tarteaucitron-wp) in versions below 0.3.0. The practical...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors WooCommerce Google Sheet Connector (GSheetConnector for WC, slug: wc-gsheetconnector) versions prior to 1.3.6 are affected by a Medium-severity Cross-Site Request Forgery (CSRF) issue tracked as CVE-2023-2329 (CVSS 4.3;...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2024-0756 is a Medium-severity stored cross-site scripting (XSS) issue (CVSS 6.4) affecting the Insert or Embed Articulate Content into WordPress plugin (versions up to and including 4.3000000023). According to the published advisory, the attack is...
by Ivan Sorkin | Feb 25, 2026 | Plugins
The 3DPrint WordPress plugin (slug: 3dprint) has a High-severity vulnerability that affects versions up to, but not including, 3.5.6.9. Tracked as CVE-2022-3899, this issue can allow an attacker to trigger arbitrary file and directory deletion if they can trick an...
Recent Comments