by Ivan Sorkin | Apr 14, 2026 | Plugins
Attack Vectors CVE-2026-5694 is a High-severity vulnerability (CVSS 7.2; vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N) affecting the Quick Interest Slider WordPress plugin (slug: quick-interest-slider) in all versions up to and including 3.1.5. The issue is an...
by Ivan Sorkin | Apr 14, 2026 | Plugins
Attack Vectors DesignO (WordPress plugin slug: designo) versions 2.2.0 and earlier are affected by a Medium-severity Cross-Site Request Forgery (CSRF) vulnerability (CVSS 4.3, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N), tracked as CVE-2025-31600. CSRF attacks rely...
by Ivan Sorkin | Apr 14, 2026 | Plugins
Attack Vectors Inquiry form to posts or pages (slug: inquiry-form-to-posts-or-pages) version 1.0 is reported as Medium severity (CVSS 4.3, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N) under CVE-2026-6293. The primary entry point is a Cross-Site Request Forgery (CSRF)...
by Ivan Sorkin | Apr 14, 2026 | Themes
Attack Vectors CVE-2026-1555 is a Critical vulnerability (CVSS 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) affecting the WebStack WordPress theme (slug: webstack) in all versions up to, and including, 1.2024. The risk is driven by the fact that an...
by Ivan Sorkin | Apr 14, 2026 | Plugins
Attack Vectors CVE-2025-49996 is a Medium-severity missing authorization issue (CVSS 5.3) affecting the WP Visitor Statistics (Real Time Traffic) plugin (slug: wp-stats-manager) in versions up to and including 8.4. Because the weakness is reachable without...
Recent Comments