Our Blog

Helping Businesses Run Better Websites — One Article at a Time

ArtPlacer Widget Vulnerability (Medium) – CVE-2026-24555

Attack Vectors CVE-2026-24555 is a Medium-severity Stored Cross-Site Scripting (XSS) issue affecting the ArtPlacer Widget WordPress plugin (slug: artplacer-widget) in versions up to and including 2.23.2. The vulnerability can be exploited by an authenticated user with...

BOX NOW Delivery Vulnerability (Medium) – CVE-2026-24571

Attack Vectors CVE-2026-24571 is a Medium-severity authorization issue (CVSS 4.3) affecting the BOX NOW Delivery WordPress plugin (box-now-delivery) in versions up to and including 3.0.2. The risk is triggered when an attacker already has a valid login (for example, a...

WPFore Subscribers