by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors CVE-2026-25418 affects the WordPress plugin Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder (slug: bit-form) in versions <= 2.21.10. The vulnerability is a Medium-severity SQL Injection (CVSS 4.9; vector...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors JAMstack Deployments (WordPress plugin slug: wp-jamstack-deployments) versions 1.1.1 and below are affected by CVE-2026-25409, a Medium-severity missing-authorization issue (CVSS 4.3; CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). The primary attack...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors Revision Manager TMC (WordPress plugin slug: revision-manager-tmc) is affected by a Medium-severity Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-25411, CVSS 4.3). CSRF attacks typically don’t require the attacker to log in; instead, they...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors CVE-2026-25408 is a Medium severity (CVSS 5.3) vulnerability affecting the Broken Link Notifier WordPress plugin (slug: broken-link-notifier) in versions <= 1.3.5. Because the issue can be triggered over the network and does not require a logged-in...
by Ivan Sorkin | Feb 26, 2026 | Plugins
Attack Vectors CVE-2026-25407 affects the WordPress plugin Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode (slug: cookiebot) in versions up to and including 4.6.4. This is a Medium severity issue (CVSS 4.3). The primary risk...
Recent Comments