by Ivan Sorkin | Apr 14, 2026 | Plugins
Attack Vectors WM JqMath (slug: wm-jqmath) versions 1.3 and below are affected by a Medium-severity Stored Cross-Site Scripting (XSS) vulnerability tracked as CVE-2026-3998 (CVSS 6.4, vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N). The attack requires an...
by Ivan Sorkin | Apr 14, 2026 | Plugins
Attack Vectors CVE-2026-3659 is a Medium severity (CVSS 6.4, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N) Stored Cross-Site Scripting (XSS) vulnerability affecting the WP Circliful WordPress plugin (slug: wp-circliful) in versions up to and including 1.2. The attack...
by Ivan Sorkin | Apr 14, 2026 | Plugins
Attack Vectors Medium-severity vulnerability (CVSS 5.3) in Katalogportal-pdf-sync Widget (slug: katalogportal-pdf-sync) affects all versions up to and including 1.0.0. An attacker does not need to trick a user into clicking anything; they only need any authenticated...
by Ivan Sorkin | Apr 14, 2026 | Plugins
Attack Vectors CVE-2026-4011 is a Medium-severity Stored Cross-Site Scripting (XSS) issue (CVSS 6.4) affecting Power Charts – Responsive Beautiful Charts & Graphs (plugin slug: wpgo-power-charts-lite) in versions <= 0.1.0. The attack requires an authenticated...
by Ivan Sorkin | Apr 14, 2026 | Plugins
Attack Vectors CVE-2026-5617 is a High-severity privilege escalation issue (CVSS 8.8) affecting Login as User – Switch User & WooCommerce Login as Customer (slug: one-click-login-as-user) in all versions up to and including 1.0.3. The attack requires an...
Recent Comments