by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors CVE-2026-24616 is a Medium severity missing authorization issue (CVSS 4.3) affecting WP Popups – WordPress Popup builder (slug: wp-popups-lite) in versions up to and including 2.2.0.5. The risk is primarily from authenticated users who already have some...
by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors CVE-2025-62980 affects the Persian Admnin Fonts WordPress plugin (slug: persian-admin-fonts) in versions 4.1.03 and below. The issue is a missing authorization (capability) check on a plugin function, which means a user who is already logged in can...
by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors CVE-2026-1614 affects the WordPress plugin Rise Blocks – A Complete Gutenberg Page Builder (slug: rise-blocks) in versions <= 3.7. It is rated Medium severity with a CVSS 6.4 score (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N), meaning it can be...
by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors LifePress (WordPress plugin slug: lifepress) versions 2.2.1 and earlier include a missing authorization control that can be reached over the network, allowing misuse through normal web requests. Because the issue affects authenticated workflows, an...
by Ivan Sorkin | Feb 24, 2026 | Plugins
Advisory: CVE-2026-24570 impacts Edwiser Bridge – WordPress Moodle Integration (plugin slug: edwiser-bridge) in versions up to and including 4.3.2. This is a Medium severity issue (CVSS 4.3; vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N) involving missing...
Recent Comments