by Ivan Sorkin | Apr 15, 2026 | Plugins
Attack Vectors AtomChat (Group Chat & Video Chat by AtomChat) version 1.1.7 and earlier has a Medium-severity authorization issue (CVE-2025-31831, CVSS 4.3) where a function is missing a capability check. In practical terms, this means an attacker does not need...
by Ivan Sorkin | Apr 15, 2026 | Plugins
Attack Vectors Brizy Pro (slug: brizy-pro) is affected by a Medium-severity reflected cross-site scripting (XSS) vulnerability (CVSS 6.1) in versions up to and including 2.8.0 (CVE-2025-22763). This type of issue is commonly exploited through social engineering: an...
by Ivan Sorkin | Apr 15, 2026 | Plugins
Attack Vectors CVE-2025-31604 is a Medium severity Stored Cross-Site Scripting (XSS) issue affecting the Cal.com WordPress plugin (slug: cal-com) in versions up to and including 1.0.0. The vulnerability can be exploited by an authenticated user with Contributor-level...
by Ivan Sorkin | Apr 15, 2026 | Plugins
Attack Vectors PostmarkApp Email Integrator (slug: postmarkapp-email-integrator) has a Medium-severity missing authorization issue (CVSS 4.3) tracked as CVE-2025-31576. The risk is primarily from authenticated users—including low-privilege accounts such as Subscriber...
by Ivan Sorkin | Apr 15, 2026 | Plugins
Attack Vectors Cliengo – Chatbot (WordPress plugin slug: cliengo) versions up to and including 3.0.4 are affected by a Medium-severity Cross-Site Request Forgery (CSRF) vulnerability (CVE-2024-37923, CVSS 5.4). CSRF attacks typically rely on social engineering: an...
Recent Comments