by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors SureForms – Contact Form, Payment Form & Other Custom Form Builder (slug: sureforms) versions <= 2.2.1 are affected by a Medium-severity missing authorization issue (CVSS 5.3). Because the weakness can be triggered by an unauthenticated user (no...
by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors Product affected: Link Whisper Free (WordPress plugin, slug: link-whisper) versions up to and including 0.9.0. This is a Medium severity vulnerability (CVSS 6.1, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) tracked as CVE-2026-22357 (CVE...
by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors CVE-2026-25368 affects the WordPress plugin Calculated Fields Form (slug: calculated-fields-form) in versions up to and including 5.4.4.1. This is a Medium severity issue (CVSS 4.3, vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). The primary...
by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors CVE-2026-25370 affects WP Compress – Instant Performance & Speed Optimization (slug: wp-compress-image-optimizer) in versions <= 6.60.28. Because this is a missing authorization issue with no privileges required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), an...
by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors CVE-2026-0929 affects the WordPress plugin RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login (slug: custom-registration-form-builder-with-submission-manager) and is rated Medium severity (CVSS 4.3;...
Recent Comments