by Ivan Sorkin | Mar 21, 2026 | Plugins
Attack Vectors CVE-2026-4314 is a High-severity privilege escalation vulnerability (CVSS 8.8, vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) affecting The Ultimate WordPress Toolkit – WP Extended (slug: wpextended) in versions up to and including 3.2.4. The...
by Ivan Sorkin | Mar 21, 2026 | Plugins
Attack Vectors CVE-2026-3629 is a High severity (CVSS 8.1) privilege-escalation vulnerability affecting the WordPress plugin Import and export users and customers (slug: import-users-from-csv-with-meta) in versions up to and including 1.29.7. An unauthenticated...
by Ivan Sorkin | Mar 20, 2026 | Plugins
Attack Vectors CVE-2026-4373 is a High-severity vulnerability (CVSS 7.5) affecting the JetFormBuilder — Dynamic Blocks Form Builder plugin (slug: jetformbuilder) in versions up to and including 3.5.6.2. An unauthenticated attacker can exploit this issue remotely by...
by Ivan Sorkin | Mar 20, 2026 | Plugins
Attack Vectors CVE-2024-13785 is a Medium-severity vulnerability (CVSS 5.6) affecting the WordPress plugin Contact Form, Survey, Quiz & Popup Form Builder – ARForms (slug: arforms-form-builder) in versions <= 1.7.2. The issue is unauthenticated, meaning an...
by Ivan Sorkin | Mar 20, 2026 | Plugins
Attack Vectors WP-WebAuthn (slug: wp-webauthn) versions 1.3.4 and earlier are affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability (severity: Medium, CVSS 6.1; vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) tracked as CVE-2025-13910....
Recent Comments