by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors WPGraphQL WooCommerce (slug: wp-graphql-woocommerce) has a medium-severity information disclosure issue (CVSS 5.3) affecting versions ≤ 0.12.3. Because the CVSS vector indicates no privileges and no user interaction are required (AV:N/PR:N/UI:N), an...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors DW Question Answer Pro (slug: dw-question-answer-pro) has a Medium-severity vulnerability (CVSS 5.4; CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) tracked as CVE-2021-24800. This issue can be exploited remotely over the network by a user who is already...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2021-24805 is a Medium-severity Cross-Site Request Forgery (CSRF) issue (CVSS 5.4) affecting DW Question & Answer Pro (slug: dw-question-answer-pro) through version 1.3.6. CSRF attacks typically rely on tricking a legitimate, logged-in user into...
by Ivan Sorkin | Feb 25, 2026 | Themes
Attack Vectors The Love Travel WordPress theme (slug: lovetravel) is affected by a Medium-severity reflected cross-site scripting (XSS) and cross-frame scripting issue in versions 2.0 through 3.7 (CVSS 6.1; vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). An...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Easy Digital Downloads – Recount Earnings (slug: edd-recount-earnings) is affected by a Medium severity Cross-Site Scripting (XSS) issue tracked as CVE-2015-9524 (CVSS 6.1, vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). This vulnerability can be...
Recent Comments