by Ivan Sorkin | Mar 20, 2026 | Plugins
Attack Vectors WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation (slug: optin) is affected by a High-severity vulnerability (CVSS 7.2, CVE-2026-4302) that can be exploited without authentication. An attacker can send crafted...
by Ivan Sorkin | Mar 20, 2026 | Plugins
Attack Vectors Product: Scoreboard for HTML5 Games Lite (WordPress plugin). Severity: Medium (CVSS 6.4; CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N). CVE: CVE-2026-4083. This issue is an authenticated Stored Cross-Site Scripting (XSS) vulnerability that requires an...
by Ivan Sorkin | Mar 20, 2026 | Plugins
Attack Vectors CVE-2026-3572 is a medium-severity vulnerability (CVSS 6.1) affecting the iTracker360 WordPress plugin (slug: itracker) in versions 2.2.0 and below. The issue combines Cross-Site Request Forgery (CSRF) with Stored Cross-Site Scripting (Stored XSS)...
by Ivan Sorkin | Mar 20, 2026 | Plugins
Attack Vectors CVE-2026-3567 is a Medium-severity vulnerability (CVSS 5.3, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) affecting RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress (slug: computer-repair-shop) in versions <= 4.1132. The risk...
by Ivan Sorkin | Mar 20, 2026 | Plugins
Attack Vectors EmailKit – Email Customizer for WooCommerce & WP (slug: emailkit) is affected by CVE-2026-3474, rated Medium severity (CVSS 4.9). The issue can be exploited by an authenticated attacker with Administrator-level (or higher) access through a REST API...
Recent Comments