by Ivan Sorkin | Feb 18, 2026 | Plugins
Attack Vectors Slider Future (WordPress plugin slug: slider-future) versions 1.0.5 and below are affected by a Critical vulnerability (CVSS 9.8) identified as CVE-2026-1405. This issue can be exploited without logging in, meaning an attacker can attempt to compromise...
by Ivan Sorkin | Feb 18, 2026 | Plugins
Attack Vectors Dealia – Request a quote (slug: dealia-request-a-quote) has a Medium severity vulnerability (CVSS 4.3) tracked as CVE-2026-2504. The risk comes from authenticated users who already have basic publishing-related access in WordPress—specifically users...
by Ivan Sorkin | Feb 18, 2026 | Plugins
Attack Vectors Easy Author Image (slug: easy-author-image) is affected by a Medium-severity stored cross-site scripting (XSS) vulnerability (CVSS 6.4; vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N) tracked as CVE-2026-1373. The key business-relevant point: an...
by Ivan Sorkin | Feb 18, 2026 | Plugins
Attack Vectors The Slidorion WordPress plugin (slug: slidorion) is affected by a Medium-severity vulnerability (CVE-2026-2282, CVSS 4.4) in versions 1.0.2 and below. The issue is an authenticated Stored Cross-Site Scripting (XSS) risk that occurs through Slidorion’s...
by Ivan Sorkin | Feb 18, 2026 | Plugins
Attack Vectors Advance Block Extend (slug: advance-block-extend) versions 1.0.4 and earlier are affected by CVE-2026-1646, a Medium severity issue (CVSS 6.4). The vulnerability enables stored cross-site scripting (XSS) through the TitleColor block attribute in the...
Recent Comments