by Ivan Sorkin | Mar 11, 2026 | Plugins
Attack Vectors CVE-2026-3231 is a High severity Stored Cross-Site Scripting (XSS) vulnerability affecting Checkout Field Editor (Checkout Manager) for WooCommerce (slug: woo-checkout-field-editor-pro) in versions <= 2.1.7 (CVSS 7.2, vector:...
by Ivan Sorkin | Mar 11, 2026 | Plugins
Attack Vectors CVE-2026-3492 affects the Gravity Forms plugin (gravityforms) in versions up to and including 2.9.28.1 and is rated Medium severity (CVSS 6.4). The issue is an authenticated (Subscriber+) stored cross-site scripting (XSS) vulnerability triggered through...
by Ivan Sorkin | Mar 11, 2026 | Core
Attack Vectors This Medium-severity vulnerability (CVSS 4.4) affects WordPress (slug: wordpress) versions up to and including 6.9.1, and involves Stored Cross-Site Scripting (XSS) through navigation menu items configured in the admin interface. To exploit it, an...
by Ivan Sorkin | Mar 11, 2026 | Plugins
Attack Vectors CVE-2026-1993 is a High-severity (CVSS 8.8) privilege escalation issue affecting ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) (slug: google-analytics-dashboard-for-wp) in versions 7.1.0 through 9.0.2. The attack...
by Ivan Sorkin | Mar 11, 2026 | Plugins
Attack Vectors CVE-2026-1992 affects ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) (slug: google-analytics-dashboard-for-wp) in versions 8.6.0 through 9.0.2. The severity is rated High (CVSS 8.8, vector...
Recent Comments