by Ivan Sorkin | Mar 18, 2026 | Plugins
Attack Vectors ValidateCertify Free (slug: validar-certificados-de-cursos) versions up to and including 1.6.4 are affected by a Cross-Site Request Forgery (CSRF) vulnerability (Medium severity; CVSS 4.3, vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N;...
by Ivan Sorkin | Mar 18, 2026 | Plugins
Attack Vectors Starfish Review Generation & Marketing for WordPress (slug: starfish-reviews) versions up to and including 3.1.19 contain a High severity vulnerability (CVSS 8.8) tracked as CVE-2025-39533. The primary attack path is straightforward for an...
by Ivan Sorkin | Mar 18, 2026 | Plugins
Attack Vectors CVE-2025-32204 is a Medium-severity vulnerability (CVSS 4.9) affecting the WordPress plugin Split Test For Elementor (slug: split-test-for-elementor) in versions <= 1.8.3. This issue is an authenticated SQL Injection, meaning an attacker must be...
by Ivan Sorkin | Mar 18, 2026 | Plugins
Attack Vectors CVE-2025-31526 is a medium-severity SQL Injection vulnerability (CVSS 6.5) affecting the Behance Portfolio Manager WordPress plugin (slug: portfolio-manager-powered-by-behance) in versions 1.7.5 and earlier. The attack requires a logged-in WordPress...
by Ivan Sorkin | Mar 18, 2026 | Plugins
Attack Vectors The vulnerability in Behance Portfolio Manager (slug: portfolio-manager-powered-by-behance) affects versions up to and including 1.7.5 and is rated Medium severity (CVSS 4.9, vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N). Exploitation requires...
Recent Comments