by Ivan Sorkin | Feb 10, 2026 | Plugins
Attack Vectors WDES Responsive Popup (slug: wdes-responsive-popup) has a Medium severity vulnerability (CVSS 6.4, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N) tracked as CVE-2026-1804. The issue affects all versions up to and including 1.3.6. The primary attack path...
by Ivan Sorkin | Feb 10, 2026 | Plugins
Attack Vectors CVE-2026-1748 affects the WordPress plugin Invoct – PDF Invoices & Billing for WooCommerce (slug: kirilkirkov-pdf-invoice-manager) in versions up to and including 1.6, with a Medium severity rating (CVSS 4.3). The issue enables an authenticated user...
by Ivan Sorkin | Feb 10, 2026 | Plugins
Attack Vectors The WordPress plugin MMA Call Tracking (slug: mma-call-tracking) is affected by a Medium severity vulnerability (CVSS 4.3) that allows Cross-Site Request Forgery (CSRF) against plugin settings in versions up to and including 2.3.15. In practical...
by Ivan Sorkin | Feb 10, 2026 | Plugins
Attack Vectors WPlyr Media Block (slug: wplyr-media-block) has a Medium-severity vulnerability (CVE-2026-0724, CVSS 4.4) affecting versions up to and including 1.3.0. This issue is a stored cross-site scripting (XSS) flaw that can be triggered through the...
by Ivan Sorkin | Feb 10, 2026 | Plugins
Attack Vectors Slideshow Wp (slug: slideshow-wp) versions 1.1 and earlier are affected by a Medium-severity issue (CVSS 6.4) tracked as CVE-2026-1885. The risk comes from a stored cross-site scripting (XSS) vulnerability tied to the sswp-slide shortcode, specifically...
Recent Comments