[email protected]
  • Pricing
  • Checkout
  • My Account
0 Items
WPFore
  • Home
  • Pricing
  • Need Support?
  • Blog
Select Page

WP Shortcodes Plugin — Shortcodes Ultimate Vulnerability (Medium) -…

by Ivan Sorkin | Apr 15, 2026 | Plugins

Attack Vectors The WP Shortcodes Plugin — Shortcodes Ultimate (slug: shortcodes-ultimate) vulnerability (CVE-2026-3885, Medium severity, CVSS 6.4) is exploitable by an authenticated WordPress user with Contributor-level access or higher. The attacker can abuse the...

StoreCustomizer – A plugin to Customize all WooCommerce Pages Vulne…

by Ivan Sorkin | Apr 15, 2026 | Plugins

Attack Vectors CVE-2026-27046 affects StoreCustomizer – A plugin to Customize all WooCommerce Pages (slug: woocustomizer) in versions <= 2.6.3. This is a Medium severity issue (CVSS 4.3, vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). The attack scenario...

Grand Wedding WordPress Vulnerability (High) – CVE-2026-22417

by Ivan Sorkin | Apr 15, 2026 | Themes

Attack Vectors CVE-2026-22417 is a High-severity vulnerability (CVSS 8.1) affecting the Grand Wedding WordPress theme (slug: grandwedding) in versions below 3.1.11. The issue can be triggered remotely over the network and does not require a user to be logged in,...

WP CTA – Call Now Button, Sticky Button & Call to Action Builder Vu…

by Ivan Sorkin | Apr 15, 2026 | Plugins

Attack Vectors CVE-2026-22459 is a Medium-severity vulnerability (CVSS 5.3) affecting the WP CTA – Call Now Button, Sticky Button & Call to Action Builder plugin (also marketed as “WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales”) in versions up to and...

Starto | Software AI Startup WordPress Vulnerability (Medium) – CVE…

by Ivan Sorkin | Apr 15, 2026 | Themes

Attack Vectors Starto (WordPress theme) versions below 2.2.5 are affected by a Medium-severity Reflected Cross-Site Scripting (XSS) issue tracked as CVE-2026-27352 (CVSS 6.1). This vulnerability can be exploited by an unauthenticated attacker by getting a user (for...
« Older Entries
Next Entries »

Recent Posts

  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • Kraken.io Image Optimizer Vulnerability (Medium) – CVE-2023-0619
  • Vantage Vulnerability (Medium) – CVE-2026-5070
  • WP Docs Vulnerability (Medium) – CVE-2026-3878

Recent Comments

    Archives

    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024

    Categories

    • Core
    • Plugins
    • Themes
    • Uncategorized
    • WooCommerce
    • WordPress Customization
    • WordPress Maintenance
    • WordPress Performance
    • WordPress Security
    • WordPress Support

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    Location

    Vrasida 5, Nicosia, Cyprus.

    (+357) 96384131

    [email protected]

    Follow Us

    • Follow
    • Follow
    • Follow
    • Follow
    • Follow
    • Follow

    Subscription

    Stay in touch and follow our latest developments.

    Success!

    Subscribe