by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2025-31640 is a Medium-severity SQL Injection vulnerability (CVSS 6.5, CVE record) affecting the Magic Responsive Slider and Carousel WordPress plugin (slug: magic-carousel) in versions <= 1.4. The key risk factor is that the attack is...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Medium severity access-control issue affecting the CSS3 Tooltips for WordPress plugin (slug: css3_tooltips) has been disclosed as CVE-2025-32180. In versions 1.8 and below, a missing authorization (capability) check can allow an authenticated user with...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2025-68046 affects the WordPress plugin Lead Form Builder & Contact Form (slug: lead-form-builder) in versions up to and including 2.0.1. The issue is rated Medium severity (CVSS 4.3). The key risk factor is that exploitation requires a valid...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2025-47557 is a Medium severity stored cross-site scripting (XSS) issue (CVSS 6.4) affecting the MapSVG WordPress plugin (slug: mapsvg) in versions up to and including 8.5.31. The vulnerability can be exploited by an authenticated user with...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2025-31922 affects the CSS3 Accordions for WordPress plugin (slug: css3_accordions) in all versions up to and including 3.0. This is a Medium-severity issue (CVSS 6.1, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). The attack path typically starts...
Recent Comments