by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2026-27542 is a Critical vulnerability (CVSS 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) impacting the Wholesale Lead Capture Plugin for WooCommerce (WordPress plugin slug: woocommerce-wholesale-lead-capture) in versions <= 1.17.8....
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2026-27541 is a High-severity privilege escalation issue (CVSS 7.2; CVE record) affecting Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices (plugin slug: woocommerce-wholesale-prices) in versions up to and including 2.2.1....
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Conditional CAPTCHA (slug: wp-conditional-captcha) is affected by CVE-2026-1369, a Medium-severity open redirect vulnerability (CVSS 5.3; CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). This issue is unauthenticated, meaning an attacker does not need a...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors ListingPro Reviews (WordPress plugin slug: listingpro-reviews) versions below 2.9.11 are affected by a Medium-severity (CVSS 6.1) reflected cross-site scripting (XSS) issue tracked as CVE-2025-69051. This vulnerability can be exploited remotely over the...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2025-62087 affects the Sticky Notes for WP Dashboard WordPress plugin (slug: wb-sticky-notes) in versions 1.2.4 and earlier. This is a Medium-severity issue (CVSS 4.3, vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). An attacker must be...
Recent Comments