by Ivan Sorkin | Mar 12, 2026 | Plugins
Attack Vectors CVE-2026-22479 is a Medium severity vulnerability (CVSS 5.3, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) affecting Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress (slug: easy-post-submission) in versions...
by Ivan Sorkin | Mar 12, 2026 | Plugins
Attack Vectors The WordPress plugin My auctions allegro (slug: my-auctions-allegro-free-edition) is affected by a Medium-severity vulnerability (CVSS 6.1) identified as CVE-2026-22491. It is a Reflected Cross-Site Scripting (XSS) issue impacting versions up to and...
by Ivan Sorkin | Mar 12, 2026 | Plugins
Attack Vectors CVE-2026-22520 is a Medium-severity (CVSS 6.1) Reflected Cross-Site Scripting (XSS) issue affecting the Handmade Framework WordPress plugin (handmade-framework) in versions up to and including 3.9. This vulnerability can be exploited by an...
by Ivan Sorkin | Mar 12, 2026 | Themes
Attack Vectors CVE-2025-69096 is a Medium-severity (CVSS 6.1) Reflected Cross-Site Scripting (XSS) vulnerability affecting the Zorka – Wonderful Fashion WooCommerce Theme (WordPress theme slug: zorka) in versions up to and including 1.5.7. This issue can be exploited...
by Ivan Sorkin | Mar 12, 2026 | Plugins
Attack Vectors CVE-2026-2466 affects the DukaPress WordPress plugin (versions <= 3.2.4) and is rated High severity with a CVSS 7.2 score (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N). The issue is an unauthenticated stored cross-site scripting (XSS) vulnerability,...
Recent Comments