by Ivan Sorkin | Feb 25, 2026 | Themes
Attack Vectors FlatNews – Responsive Magazine WordPress Theme (slug: flatnews) has a Medium-severity vulnerability (CVE-2025-32305, CVSS 6.1) that can be exploited by unauthenticated attackers through reflected cross-site scripting (XSS). In practical terms, this type...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2025-68047 is a High-severity vulnerability (CVSS 7.5) affecting Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) (WordPress plugin slug: wp-event-solution) in versions up to and including 4.1.3. This issue is...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Attesa Extra (slug: attesa-extra) has a Medium severity vulnerability (CVSS 6.4, CVE-2025-62971) affecting versions up to and including 1.4.7. It is an authenticated Stored Cross-Site Scripting (XSS) issue, meaning an attacker must be logged into...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Premmerce Wholesale Pricing for WooCommerce (slug: premmerce-woocommerce-wholesale-pricing) versions 1.1.10 and earlier contain a Medium-severity missing-authorization issue (CVE-2025-64285, CVSS 4.3). The key risk is that an authenticated WordPress...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2025-64291 is a Medium-severity Stored Cross-Site Scripting (XSS) issue in the Premmerce User Roles WordPress plugin (slug: premmerce-user-roles) affecting versions up to and including 1.0.13 (CVSS 3.1: 4.4, vector:...
Recent Comments