by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors CVE-2026-25388 affects the Ads Pro Plugin – Multi-Purpose WordPress Advertising Manager (slug: ap-plugin-scripteo) in versions up to and including 5.0. This is rated Medium severity with a CVSS 4.3 score...
by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors CVE-2026-23693 is a Medium severity (CVSS 5.3) issue affecting the WordPress plugin ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (slug: elementskit-lite). Because the CVSS vector indicates no privileges required...
by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors GLS Shipping for WooCommerce (slug: gls-shipping-for-woocommerce) is affected by a Medium-severity reflected cross-site scripting (XSS) issue (CVE-2025-68011) in versions <= 1.4.0 (CVSS 6.1). Because it is reflected XSS, an attacker typically...
by Ivan Sorkin | Feb 24, 2026 | Plugins
Attack Vectors CVE-2025-66134 affects the FileBird Pro WordPress plugin (versions up to and including 6.5.1) and is rated Medium severity (CVSS 4.3; vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). The risk comes from authenticated access: an attacker would need...
by Ivan Sorkin | Feb 23, 2026 | Plugins
The WP Gravity Forms Keap/Infusionsoft WordPress plugin (gf-infusionsoft) has a Medium-severity Open Redirect vulnerability (CVSS 4.3) tracked as CVE-2025-58006. Affected versions include all versions up to and including 1.2.4. According to the published advisory,...
Recent Comments